CVE-2024-2243

HIGH

csmock < 3.5.3 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.

Scores

CVSS v3 7.6
EPSS 0.0105
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
csutils/csmock < 3.5.3
Published Apr 10, 2024
Tracked Since Feb 18, 2026