PT-2024-5209 · Cocoapods · Cocoapods

B4Rd4K

+1

·

Published

2024-07-01

·

Updated

2025-04-10

·

CVE-2024-38367

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CocoaPods (affected versions not specified)
Description: The issue is related to the authentication server for the CocoaPods dependency manager, where the trunk sessions verification step could be manipulated, allowing for owner session hijacking. This could result in a full takeover of the CocoaPods trunk account, enabling the threat actor to manipulate pod specifications, disrupt the distribution of legitimate libraries, or cause widespread disruption within the CocoaPods ecosystem.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2024-05770
CVE-2024-38367
GHSA-52GF-M7V9-M333

Affected Products

Cocoapods