CVE-2024-53829

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Jan 21, 2025
CWE ID 352

Summary

CVE-2024-53829 is a cross-site request forgery (CSRF) vulnerability affecting CodeChecker, an analyzer tool and extension for Clang Static Analyzer and Clang Tidy. An unauthenticated attacker can exploit this flaw to hijack the authentication of a logged-in user and manipulate the web API, allowing them to add, remove, or edit products. The attacker must know the IDs of the available products to modify or delete them. This vulnerability does not enable the attacker to directly exfiltrate data, as it is limited to form-based CSRF attacks. CodeChecker versions up to and including 6.24.4 are affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share