Description
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and since `0.5.0`, before `0.15.0`. The vulnerability stems from a Python function, `cdo_local_uuid.local_uuid()`, and its original implementation `case_utils.local_uuid()`.
References (14)
Core 14
Core References
Exploit, Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/security/advisories/GHSA-rgrf-6mf5-m882
Patch x_refsource_misc
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/3
Patch x_refsource_misc
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/4
Patch x_refsource_misc
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/commit/9e78f7cb1075728d0aafc918514f32a1392cd235
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/00864cd12de7c50d882dd1a74915d32e939c25f9
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/1cccae8eb3cf94b3a28f6490efa0fbf5c82ebd6b
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/5acb929dfb599709d1c8c90d1824dd79e0fd9e10
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/7e02d18383eabbeb9fb4ec97d81438c9980a4790
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/80551f49241c874c7c50e14abe05c5017630dad2
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/939775f956796d0432ecabbf62782ed7ad1007b5
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/db428a0745dac4fdd888ced9c52f617695519f9d
Patch x_refsource_misc
https://github.com/casework/CASE-Utilities-Python/commit/e4ffadc3d56fd303b8f465d727c4a58213d311a1
Scores
CVSS v3
2.2
EPSS
0.0003
EPSS Percentile
8.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-337
CWE-215
Status
published
Products (13)
lfprojects/case_python_utilities
0.5.0
lfprojects/case_python_utilities
0.6.0
lfprojects/case_python_utilities
0.7.0
lfprojects/case_python_utilities
0.8.0
lfprojects/case_python_utilities
0.9.0
lfprojects/case_python_utilities
0.10.0
lfprojects/case_python_utilities
0.11.0
lfprojects/case_python_utilities
0.12.0
lfprojects/case_python_utilities
0.13.0
lfprojects/case_python_utilities
0.14.0
... and 3 more
Published
Jan 11, 2024
Tracked Since
Feb 18, 2026