CVE-2024-2243 HIGH

CVE-2024-2243: Csmock: command injection vulnerability in csmock-plugin-snyk

Weakness CWE-78
Published April 10, 2024
Last update November 4, 2025

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

What the vulnerability does

01Description

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.

Key dates

02Disclosure timeline

April 10, 2024 CVE published
November 4, 2025 Record updated