CVE-2024-28120
CVSS V2 None
CVSS V3 None
Description
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker to host a website that will steal the user's Codeium api-key, and thus impersonate the user on the backend autocomplete server. This issue has not been addressed. Users are advised to monitor the usage of their API key.
Overview
- CVE ID
- CVE-2024-28120
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-03-11T21:14:22.675Z
- Last Modified Date
- 2024-06-04T18:04:00.650Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/Exafunction/codeium-chrome/security/advisories/GHSA-8c7j-2h97-q63p | x_refsource_CONFIRM |
https://securitylab.github.com/advisories/GHSL-2024-027_GHSL-2024-028_codeium-chrome | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-28120 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28120 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 07:37:46 | Added to TrackCVE |