CVE-2024-42370

CVSS V2 None CVSS V3 None
Description
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the `DOCS_PREVIEW_DEPLOY_TOKEN` is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue.
Overview
  • CVE ID
  • CVE-2024-42370
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-09T18:29:11.205Z
  • Last Modified Date
  • 2024-08-09T19:10:02.612Z
History
Created Old Value New Value Data Type Notes
2024-08-10 13:09:19 Added to TrackCVE