CVE-2024-29042
Last modified
CVE-2024-29042 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling the second variable of the `translate` function is able to perform a cache poisoning attack. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling the second variable of the `translate` function is able to perform a cache poisoning attack. They can change the outcome of translation requests made by subsequent users. The `opt.id` parameter allows the overwriting of the cache key. If an attacker sets the `id` variable to the cache key that would be generated by another user, they can choose the response that user gets served. Version 3.0.0 fixes this issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Francisco | Translate | < 3.0.0 |
References
- https://github.com/franciscop/translate/security/advisories/GHSA-882j-4vj5-7vmjExploit, Vendor Advisory
- https://github.com/franciscop/translate/security/advisories/GHSA-882j-4vj5-7vmjExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29042?
How severe is CVE-2024-29042?
How do I fix CVE-2024-29042?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-29037datahub-helm provides the Kubernetes Helm charts for deployi…9.1
- CVE-2024-29038tpm2-tools is the source repository for the Trusted Platform…3.3
- CVE-2024-29039tpm2 is the source repository for the Trusted Platform Modul…8.1
- CVE-2024-2904Cross-Site Request Forgery (CSRF) vulnerability in Extend Th…8.8
- CVE-2024-29040This repository hosts source code implementing the Trusted C…4.3
- CVE-2024-29041Express.js minimalist web framework for node. Versions of Ex…6.1
- CVE-2024-29043Microsoft ODBC Driver for SQL Server Remote Code Execution V…8.8
- CVE-2024-29044Microsoft OLE DB Driver for SQL Server Remote Code Execution…8.8
- CVE-2024-29045Microsoft OLE DB Driver for SQL Server Remote Code Execution…7.5
- CVE-2024-29046Microsoft OLE DB Driver for SQL Server Remote Code Execution…8.8
- CVE-2024-29047Microsoft OLE DB Driver for SQL Server Remote Code Execution…8.8
- CVE-2024-29048Microsoft OLE DB Driver for SQL Server Remote Code Execution…8.8
Are you affected by CVE-2024-29042?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
