CVE-2024-31455

MEDIUM

Stacklok Minder < 0.0.40 - Information Disclosure

Title source: rule
STIX 2.1

Description

Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository. This issue is patched in pull request 2941. As a workaround, revert prior to `5c381cf`, or roll forward past `2eb94e7`.

Scores

CVSS v3 4.3
EPSS 0.0045
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
stacklok/minder 0.0.39 - 0.0.40Go
stacklok/minder = 0.0.39
Published Apr 09, 2024
Tracked Since Feb 18, 2026