← Zuruck zu CVEs
CVE-2024-53829
HIGH8.2
Beschreibung
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a logged in user, and use the web API with the same permissions, including but not limited to adding, removing or editing products. The attacker needs to know the ID of the available products to modify or delete them. The attacker cannot directly exfiltrate data (view) from CodeChecker, due to being limited to form-based CSRF. This issue affects CodeChecker: through 6.24.4.
CVE Details
CVSS v3.1 Bewertung8.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht1/21/2025
Zuletzt geandert11/14/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
ericsson:codechecker
Schwachen (CWE)
CWE-352
Referenzen
https://github.com/Ericsson/codechecker/security/advisories/GHSA-f8c8-4pm7-w885(85b1779b-6ecd-4f52-bcc5-73eac4659dcf)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.