PT-2024-31779 · Arduino · Arduino-Esp32

Pwntester

·

Published

2024-09-17

·

Updated

2024-09-20

·

CVE-2024-45798

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: arduino-esp32 (affected versions not specified)
Description: The issue concerns multiple Poisoned Pipeline Execution (PPE) vulnerabilities in the arduino-esp32 CI, including code injection in the tests results.yml workflow and environment variable injection. These vulnerabilities have the potential for repository takeover and enable remote attacks with high impact. Users are advised to verify the contents of the downloaded artifacts.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-45798
GHSA-H52Q-XHG2-6JW8

Affected Products

Arduino-Esp32