PT-2024-31779 · Arduino · Arduino-Esp32
Pwntester
·
Published
2024-09-17
·
Updated
2024-09-20
·
CVE-2024-45798
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
arduino-esp32 (affected versions not specified)
Description:
The issue concerns multiple Poisoned Pipeline Execution (PPE) vulnerabilities in the arduino-esp32 CI, including code injection in the
tests results.yml workflow and environment variable injection. These vulnerabilities have the potential for repository takeover and enable remote attacks with high impact. Users are advised to verify the contents of the downloaded artifacts.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arduino-Esp32