PT-2024-2625 · Unknown · Codeium-Chrome

Kwstubbs

·

Published

2024-03-11

·

Updated

2024-03-13

·

CVE-2024-28120

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions codeium-chrome (affected versions not specified)
Description The issue is related to the lack of protection for service data in the codeium-chrome plugin. An attacker can exploit this to send arbitrary requests to the internal autocomplete server on behalf of another user. The service worker of the codeium-chrome extension does not check the sender when receiving an external message, allowing an attacker to steal the user's Codeium API key and impersonate the user on the backend autocomplete server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider monitoring the usage of your API key to minimize the risk of exploitation. Restrict access to the Codeium API key to prevent unauthorized use until the issue is resolved.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-02692
CVE-2024-28120
GHSA-8C7J-2H97-Q63P

Affected Products

Codeium-Chrome