CVE-2024-48964 HIGH

CVE-2024-48964

Vendor Snyk
Product Snyk Cli
Weakness CWE-78
Published October 23, 2024
Last update October 24, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.

Key dates

02Disclosure timeline

October 23, 2024 CVE published
October 24, 2024 Record updated