Executive Summary

Informations
Name CVE-2024-38368 First vendor Publication 2024-07-01
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
Overall CVSS Score 9.3
Base Score 9.3 Environmental Score 9.3
impact SubScore 4.7 Temporal Score 9.3
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Changed Confidentiality Impact None
Integrity Impact High Availability Impact Low
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also possible to have all owners removed from a pod, and that made the pod available for the same claiming system. This was patched server-side in commit 71be5440906b6bdfbc0bcc7f8a9fec33367ea0f4 in September 2023.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38368

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Sources (Detail)

https://blog.cocoapods.org/Claim-Your-Pods
https://blog.cocoapods.org/CocoaPods-Trunk-RCEs-2023
https://evasec.webflow.io/blog/eva-discovered-supply-chain-vulnerabities-in-c...
https://github.com/CocoaPods/CocoaPods/security/advisories/GHSA-j483-qm5c-7hqx
https://github.com/CocoaPods/trunk.cocoapods.org/commit/71be5440906b6bdfbc0bc...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2024-11-25 05:23:47
  • Multiple Updates
2024-09-18 21:27:48
  • Multiple Updates
2024-07-02 17:27:26
  • Multiple Updates
2024-07-02 00:27:26
  • First insertion