CVE-2024-22194

cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and since `0.5.0`, before `0.15.0`. The vulnerability stems from a Python function, `cdo_local_uuid.local_uuid()`, and its original implementation `case_utils.local_uuid()`.
References
Link Resource
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/commit/9e78f7cb1075728d0aafc918514f32a1392cd235 Patch
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/3 Patch
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/4 Patch
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/security/advisories/GHSA-rgrf-6mf5-m882 Exploit Mitigation Third Party Advisory
https://github.com/casework/CASE-Utilities-Python/commit/00864cd12de7c50d882dd1a74915d32e939c25f9 Patch
https://github.com/casework/CASE-Utilities-Python/commit/1cccae8eb3cf94b3a28f6490efa0fbf5c82ebd6b Patch
https://github.com/casework/CASE-Utilities-Python/commit/5acb929dfb599709d1c8c90d1824dd79e0fd9e10 Patch
https://github.com/casework/CASE-Utilities-Python/commit/7e02d18383eabbeb9fb4ec97d81438c9980a4790 Patch
https://github.com/casework/CASE-Utilities-Python/commit/80551f49241c874c7c50e14abe05c5017630dad2 Patch
https://github.com/casework/CASE-Utilities-Python/commit/939775f956796d0432ecabbf62782ed7ad1007b5 Patch
https://github.com/casework/CASE-Utilities-Python/commit/db428a0745dac4fdd888ced9c52f617695519f9d Patch
https://github.com/casework/CASE-Utilities-Python/commit/e4ffadc3d56fd303b8f465d727c4a58213d311a1 Patch
https://github.com/casework/CASE-Utilities-Python/commit/fca7388f09feccd3b9ea88e6df9c7a43a5349452 Patch
https://github.com/casework/CASE-Utilities-Python/commit/fdc32414eccfcbde6be0fd91b7f491cc0779b02d#diff-e60b9cb8fb480ed27283a030a0898be3475992d78228f4045b12ce5cbb2f0509 Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lfprojects:case_python_utilities:0.5.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.6.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.7.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.8.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.9.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.10.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.11.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.12.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.13.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.14.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:cdo_local_uuid_utility:0.4.0:*:*:*:*:python:*:*

History

19 Jan 2024, 19:03

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 2.2
v2 : unknown
v3 : 2.8
First Time Lfprojects
Lfprojects case Python Utilities
Lfprojects cdo Local Uuid Utility
References () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/commit/9e78f7cb1075728d0aafc918514f32a1392cd235 - () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/commit/9e78f7cb1075728d0aafc918514f32a1392cd235 - Patch
References () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/3 - () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/3 - Patch
References () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/4 - () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/4 - Patch
References () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/security/advisories/GHSA-rgrf-6mf5-m882 - () https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/security/advisories/GHSA-rgrf-6mf5-m882 - Exploit, Mitigation, Third Party Advisory
References () https://github.com/casework/CASE-Utilities-Python/commit/00864cd12de7c50d882dd1a74915d32e939c25f9 - () https://github.com/casework/CASE-Utilities-Python/commit/00864cd12de7c50d882dd1a74915d32e939c25f9 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/1cccae8eb3cf94b3a28f6490efa0fbf5c82ebd6b - () https://github.com/casework/CASE-Utilities-Python/commit/1cccae8eb3cf94b3a28f6490efa0fbf5c82ebd6b - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/5acb929dfb599709d1c8c90d1824dd79e0fd9e10 - () https://github.com/casework/CASE-Utilities-Python/commit/5acb929dfb599709d1c8c90d1824dd79e0fd9e10 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/7e02d18383eabbeb9fb4ec97d81438c9980a4790 - () https://github.com/casework/CASE-Utilities-Python/commit/7e02d18383eabbeb9fb4ec97d81438c9980a4790 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/80551f49241c874c7c50e14abe05c5017630dad2 - () https://github.com/casework/CASE-Utilities-Python/commit/80551f49241c874c7c50e14abe05c5017630dad2 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/939775f956796d0432ecabbf62782ed7ad1007b5 - () https://github.com/casework/CASE-Utilities-Python/commit/939775f956796d0432ecabbf62782ed7ad1007b5 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/db428a0745dac4fdd888ced9c52f617695519f9d - () https://github.com/casework/CASE-Utilities-Python/commit/db428a0745dac4fdd888ced9c52f617695519f9d - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/e4ffadc3d56fd303b8f465d727c4a58213d311a1 - () https://github.com/casework/CASE-Utilities-Python/commit/e4ffadc3d56fd303b8f465d727c4a58213d311a1 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/fca7388f09feccd3b9ea88e6df9c7a43a5349452 - () https://github.com/casework/CASE-Utilities-Python/commit/fca7388f09feccd3b9ea88e6df9c7a43a5349452 - Patch
References () https://github.com/casework/CASE-Utilities-Python/commit/fdc32414eccfcbde6be0fd91b7f491cc0779b02d#diff-e60b9cb8fb480ed27283a030a0898be3475992d78228f4045b12ce5cbb2f0509 - () https://github.com/casework/CASE-Utilities-Python/commit/fdc32414eccfcbde6be0fd91b7f491cc0779b02d#diff-e60b9cb8fb480ed27283a030a0898be3475992d78228f4045b12ce5cbb2f0509 - Patch
CPE cpe:2.3:a:lfprojects:case_python_utilities:0.7.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.8.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.6.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.10.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.5.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.11.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.12.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.13.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.14.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:cdo_local_uuid_utility:0.4.0:*:*:*:*:python:*:*
cpe:2.3:a:lfprojects:case_python_utilities:0.9.0:*:*:*:*:python:*:*

11 Jan 2024, 13:57

Type Values Removed Values Added
Summary
  • (es) El proyecto cdo-local-uuid proporciona una función especializada de generación de UUID que puede, a petición del usuario, hacer que un programa genere UUID deterministas. Una vulnerabilidad de fuga de información está presente en `cdo-local-uuid` en la versión `0.4.0`, y en `case-utils` en versiones sin parches (que coinciden con el patrón `0.x.0`) en y desde `0.5. 0`, antes de `0.15.0`. La vulnerabilidad surge de una función de Python, `cdo_local_uuid.local_uuid()`, y su implementación original `case_utils.local_uuid()`.

11 Jan 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-11 03:15

Updated : 2024-01-19 19:03


NVD link : CVE-2024-22194

Mitre link : CVE-2024-22194

CVE.ORG link : CVE-2024-22194


JSON object : View

Products Affected

lfprojects

  • case_python_utilities
  • cdo_local_uuid_utility
CWE
CWE-215

Insertion of Sensitive Information Into Debugging Code

CWE-337

Predictable Seed in Pseudo-Random Number Generator (PRNG)