CVE-2024-22194

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/01/2024
Last modified:
19/01/2024

Description

cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and since `0.5.0`, before `0.15.0`. The vulnerability stems from a Python function, `cdo_local_uuid.local_uuid()`, and its original implementation `case_utils.local_uuid()`.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lfprojects:case_python_utilities:0.5.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.6.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.7.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.8.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.9.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.10.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.11.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.12.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.13.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.14.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:cdo_local_uuid_utility:0.4.0:*:*:*:*:python:*:*