CVE-2024-31455

MEDIUM4.3EPSS 0.45%

Minder GetRepositoryByName data leak

Published: 4/9/2024Modified: 6/4/2024
Also known as:GHSA-ggp5-28x4-xcj9GO-2024-2701

Description

### Impact A recent refactoring added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository. ### Patches Patched in #2941 ### Workarounds Revert prior to `5c381cf`, or roll forward past `2eb94e7` ### References N/A

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (6)