Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2492 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the `DOCS_PREVIEW_DEPLOY_TOKEN` is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue. |
Github GHSA |
GHSA-4hq2-rpgc-r8r7 | Withdrawn Advisory: Litestar has an environment Variable injection in `docs-preview.yml` workflow |
Mon, 19 Aug 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Litestar repository workflow vulnerable to Environment Variable injection in `docs-preview.yml` workflow | Litestar repository vulnerable to Environment Variable injection in `docs-preview.yml` workflow |
Mon, 19 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Litestar vulnerable to Environment Variable injection in `docs-preview.yml` workflow | Litestar repository workflow vulnerable to Environment Variable injection in `docs-preview.yml` workflow |
Mon, 12 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Litestar-org
Litestar-org litestar |
|
| CPEs | cpe:2.3:a:litestar-org:litestar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Litestar-org
Litestar-org litestar |
|
| Metrics |
ssvc
|
Fri, 09 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue will grant a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the `DOCS_PREVIEW_DEPLOY_TOKEN` is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue. | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the `DOCS_PREVIEW_DEPLOY_TOKEN` is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue. |
Fri, 09 Aug 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue will grant a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the `DOCS_PREVIEW_DEPLOY_TOKEN` is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue. | |
| Title | Litestar vulnerable to Environment Variable injection in `docs-preview.yml` workflow | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-19T21:05:05.131Z
Reserved: 2024-07-30T14:01:33.923Z
Link: CVE-2024-42370
Updated: 2024-08-12T17:31:46.011Z
Status : Deferred
Published: 2024-08-12T13:38:34.497
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-42370
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA