PT-2024-30541 · Unknown · Trufflehog

Abankalarm

·

Published

2024-08-19

·

Updated

2025-03-14

·

CVE-2024-43379

CVSS v3.1

3.4

Low

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions TruffleHog versions prior to 3.81.9
Description This issue allows a malicious actor to craft data in a way that, when scanned by specific detectors, could trigger the detector to make an unauthorized request to an endpoint chosen by the attacker. For an exploit to be effective, the target endpoint must be an unauthenticated GET endpoint that produces side effects. The victim must scan the maliciously crafted data and have such an endpoint targeted for the exploit to succeed.
Recommendations For versions prior to 3.81.9, upgrade to TruffleHog v3.81.9 or a later version to mitigate the issue. As a temporary workaround, consider restricting access to unauthenticated GET endpoints that produce side effects until a patch is applied. Avoid scanning maliciously crafted data with specific detectors until the issue is resolved.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43379
GHSA-3R74-V83P-F4F4
GO-2024-3076

Affected Products

Trufflehog