CVE-2024-38353
Last modified
CVE-2024-38353 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain unauthorised access to image data uploaded to CodiMD. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain unauthorised access to image data uploaded to CodiMD. CodiMD does not require valid authentication to access uploaded images or to upload new image data. An attacker who can determine an uploaded image's URL can gain unauthorised access to uploaded image data. Due to the insecure random filename generation in the underlying Formidable library, an attacker can determine the filenames for previously uploaded images and the likelihood of this issue being exploited is increased. This vulnerability is fixed in 2.5.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hackmd | Codimd | < 2.5.4 |
References
- https://github.com/hackmdio/codimd/security/advisories/GHSA-2764-jppc-p2hmExploit, Mitigation, Third Party Advisory
- https://github.com/hackmdio/codimd/security/advisories/GHSA-2764-jppc-p2hmExploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-38353?
How severe is CVE-2024-38353?
How do I fix CVE-2024-38353?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-38345A cross-site request forgery vulnerability exists in Sola Te…8.1
- CVE-2024-38346The CloudStack cluster service runs on unauthenticated port …9.8
- CVE-2024-38347CodeProjects Health Care hospital Management System v1.0 was…8.8
- CVE-2024-38348CodeProjects Health Care hospital Management System v1.0 was…8.8
- CVE-2024-38351Pocketbase is an open source web backend written in go. In a…5.4
- CVE-2024-38352Rejected reason: CVE was assigned in error.
- CVE-2024-38354CodiMD allows realtime collaborative markdown notes on all p…6.1
- CVE-2024-38355Socket.IO is an open source, real-time, bidirectional, event…7.3
- CVE-2024-38356TinyMCE is an open source rich text editor. A cross-site scr…6.1
- CVE-2024-38357TinyMCE is an open source rich text editor. A cross-site scr…6.1
- CVE-2024-38358Wasmer is a web assembly (wasm) Runtime supporting WASIX, WA…2.9
- CVE-2024-38359The Lightning Network Daemon (lnd) - is a complete implement…6.5
Are you affected by CVE-2024-38353?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
