PT-2024-2625 · Unknown · Codeium-Chrome
Kwstubbs
·
Published
2024-03-11
·
Updated
2024-03-13
·
CVE-2024-28120
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
codeium-chrome (affected versions not specified)
Description
The issue is related to the lack of protection for service data in the codeium-chrome plugin. An attacker can exploit this to send arbitrary requests to the internal autocomplete server on behalf of another user. The service worker of the codeium-chrome extension does not check the sender when receiving an external message, allowing an attacker to steal the user's Codeium API key and impersonate the user on the backend autocomplete server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider monitoring the usage of your API key to minimize the risk of exploitation. Restrict access to the
Codeium API key to prevent unauthorized use until the issue is resolved.Exploit
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codeium-Chrome