CVE-2024-9825

CVSS V2 None CVSS V3 None
Description
The Chef Habitat builder-api on-prem-builder package  with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token.  Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package. The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.
Overview
  • CVE ID
  • CVE-2024-9825
  • Assigner
  • ProgressSoftware
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-28T18:42:39.786Z
  • Last Modified Date
  • 2024-10-28T18:46:45.420Z
History
Created Old Value New Value Data Type Notes
2024-10-29 13:39:36 Added to TrackCVE