CVE-2024-39314

MEDIUM

toy-blog <0.5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command line parameter. The problem was patched in version 0.5.0. As a workaround, pass `--read-bearer-token-from-stdin` to the launch arguments and feed the token from the standard input in version 0.4.14 or later. Earlier versions do not have this workaround.

Scores

CVSS v3 4.7
EPSS 0.0009
EPSS Percentile 25.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-214
Status published
Products (1)
KisaragiEffective/toy-blog >= 0.4.3, < 0.5.0
Published Jul 01, 2024
Tracked Since Feb 18, 2026