PT-2024-24749 · Hydra · Hydra

Delroth

·

Published

2024-04-22

·

Updated

2024-04-23

·

CVE-2024-32657

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hydra versions prior to the fix commit applied around 2024-04-21 14:30 UTC
Description Hydra, a Continuous Integration service for Nix-based projects, has an issue that allows attackers to execute arbitrary code in the browser context and execute authenticated HTTP requests. The problem arises from a feature that lets Nix builds specify files served by Hydra to clients, particularly affecting HTML files. This issue can be worked around by not opening HTML build artifacts until the vulnerability is fixed.
Recommendations For versions prior to the fix commit, apply the fix commit to local installations to resolve the issue. For users of the nixpkgs package, update to unstable or 23.11 to obtain the fixed version. As a temporary workaround, consider not opening HTML build artifacts until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-32657
GHSA-2P75-6G9F-PQGX

Affected Products

Hydra