CVE-2024-53829
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2024-53829 is a cross-site request forgery (CSRF) vulnerability affecting CodeChecker, an analyzer tool and extension for Clang Static Analyzer and Clang Tidy. An unauthenticated attacker can exploit this flaw to hijack the authentication of a logged-in user and manipulate the web API, allowing them to add, remove, or edit products. The attacker must know the IDs of the available products to modify or delete them. This vulnerability does not enable the attacker to directly exfiltrate data, as it is limited to form-based CSRF attacks. CodeChecker versions up to and including 6.24.4 are affected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Telefonaktiebolaget LM Ericsson