Vulnerability Details CVE-2024-43379
TruffleHog is a secrets scanning tool. Prior to v3.81.9, this vulnerability allows a malicious actor to craft data in a way that, when scanned by specific detectors, could trigger the detector to make an unauthorized request to an endpoint chosen by the attacker. For an exploit to be effective, the target endpoint must be an unauthenticated GET endpoint that produces side effects. The victim must scan the maliciously crafted data and have such an endpoint targeted for the exploit to succeed. The vulnerability has been resolved in TruffleHog v3.81.9 and later versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.1%
CVSS Severity
CVSS v3 Score 3.4
Products affected by CVE-2024-43379
-
cpe:2.3:a:trufflesecurity:trufflehog:-
-
cpe:2.3:a:trufflesecurity:trufflehog:0.1.0
-
cpe:2.3:a:trufflesecurity:trufflehog:2.0.97
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.0.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.1.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.10.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.10.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.10.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.10.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.10.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.11.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.11.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.12.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.12.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.13.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.14.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.15
-
cpe:2.3:a:trufflesecurity:trufflehog:3.15.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.15.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.16.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.16.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.16.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.16.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.16.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.17.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.18.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.19.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.2.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.2.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.2.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.2.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.20.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.21.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.21.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.22.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.23.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.24.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.25.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.25.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.25.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.25.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.25.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.26.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.27.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.27.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.28.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.29.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.29.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.3.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.3.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.3.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.3.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.30.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.31.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.32.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.32.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.32.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.33.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.34.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.35.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.36.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.37.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.38.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.39.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.4.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.4.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.4.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.4.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.4.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.4.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.40.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.41.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.41.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.42.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.43.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.44.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.45.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.45.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.45.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.45.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.46.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.46.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.46.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.46.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.47.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.48.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.49.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.5.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.50.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.51.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.52.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.52.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.53.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.54.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.54.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.54.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.54.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.54.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.55.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.55.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.56.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.56.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.57.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.58.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.59.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.10
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.11
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.8
-
cpe:2.3:a:trufflesecurity:trufflehog:3.6.9
-
cpe:2.3:a:trufflesecurity:trufflehog:3.60.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.60.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.60.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.60.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.60.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.61.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.62.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.62.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.10
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.11
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.8
-
cpe:2.3:a:trufflesecurity:trufflehog:3.63.9
-
cpe:2.3:a:trufflesecurity:trufflehog:3.64.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.65.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.66.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.66.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.66.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.66.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.67.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.68.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.68.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.68.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.68.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.68.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.68.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.69.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.7.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.7.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.7.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.7.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.70.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.70.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.70.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.70.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.71.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.71.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.71.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.72.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.73.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.74.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.75.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.75.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.76.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.76.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.76.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.76.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.77.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.78.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.78.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.78.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.79.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.8.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.80.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.0
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.1
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.2
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.3
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.4
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.5
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.6
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.7
-
cpe:2.3:a:trufflesecurity:trufflehog:3.81.8
-
cpe:2.3:a:trufflesecurity:trufflehog:3.9.0