PT-2024-30541 · Unknown · Trufflehog
Abankalarm
·
Published
2024-08-19
·
Updated
2025-03-14
·
CVE-2024-43379
CVSS v3.1
3.4
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TruffleHog versions prior to 3.81.9
Description
This issue allows a malicious actor to craft data in a way that, when scanned by specific detectors, could trigger the detector to make an unauthorized request to an endpoint chosen by the attacker. For an exploit to be effective, the target endpoint must be an unauthenticated GET endpoint that produces side effects. The victim must scan the maliciously crafted data and have such an endpoint targeted for the exploit to succeed.
Recommendations
For versions prior to 3.81.9, upgrade to TruffleHog v3.81.9 or a later version to mitigate the issue.
As a temporary workaround, consider restricting access to unauthenticated GET endpoints that produce side effects until a patch is applied.
Avoid scanning maliciously crafted data with specific detectors until the issue is resolved.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trufflehog