CVE-2024-52582

MEDIUM

Cachi2 <0.14.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build process network-isolated. Prior to version 0.14.0, secrets may be shown in logs when an unhandled exception is triggered because the tool is logging locals of each function. This may uncover secrets if tool used in CI/build pipelines as it's the main use case. Version 0.14.0 contains a patch for the issue. No known workarounds are available.

Scores

CVSS v3 4.7
EPSS 0.0010
EPSS Percentile 27.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
containerbuildsystem/cachi2 < 0.14.0
Published Nov 19, 2024
Tracked Since Feb 18, 2026