{"id":"CVE-2024-2243","summary":"Csmock: command injection vulnerability in csmock-plugin-snyk","details":"A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.","modified":"2026-08-12T03:51:47.371543632Z","published":"2024-04-10T10:14:47.671Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2243.json","cna_assigner":"fedora"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I5MJC7U2ZKXUZWELQUJSN56WL5IM4MDR/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TIBNRL3LTG747DNWTBCPRSNRPKOBANMX/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3HF6YTEGGW3SWB4V7JUVIRCXIBRHR7A/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-2243"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2243.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-2243"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2267336"},{"type":"PACKAGE","url":"https://github.com/csutils/csmock"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/csutils/csmock","events":[{"introduced":"802bbf3f719b2c3ed52b8d9175a8cc0120cff609"},{"fixed":"b3503d48696cb2ec8eb2fb379fb57c141f08e8da"}],"database_specific":{"cpe":"cpe:2.3:a:csutils:csmock:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.5.2"},{"last_affected":"3.5.2"},{"introduced":"3.5.1"},{"last_affected":"3.5.1"},{"introduced":"0"},{"fixed":"3.5.3"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["3.5.1","3.5.2","csmock-3.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-2243.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"}]}