CVE-2024-40637
Last modified
CVE-2024-40637 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs a package in dbt, it has the ability to override macros, materializations, and other core components of dbt. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs a package in dbt, it has the ability to override macros, materializations, and other core components of dbt. This is by design, as it allows packages to extend and customize dbt's functionality. However, this also means that a malicious package could potentially override these components with harmful code. This issue has been fixed in versions 1.8.0, 1.6.14 and 1.7.14. Users are advised to upgrade. There are no kn own workarounds for this vulnerability. Users updating to either 1.6.14 or 1.7.14 will need to set `flags.require_explicit_package_overrides_for_builtin_materializations: False` in their configuration in `dbt_project.yml`.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Getdbt | Dbt Core | < 1.6.14 |
| Getdbt | Dbt Core | >= 1.7.0, < 1.7.14 |
References
- https://tempered.works/posts/2024/07/06/preventing-data-theft-with-gcp-service-controlsExploit, Third Party Advisory
- https://www.elementary-data.com/post/are-dbt-packages-secure-the-answer-lies-in-your-dwh-policiesExploit, Third Party Advisory
- https://www.equalexperts.com/blog/tech-focus/are-you-at-risk-from-this-critical-dbt-vulnerabilityExploit, Third Party Advisory
- https://tempered.works/posts/2024/07/06/preventing-data-theft-with-gcp-service-controlsExploit, Third Party Advisory
- https://www.elementary-data.com/post/are-dbt-packages-secure-the-answer-lies-in-your-dwh-policiesExploit, Third Party Advisory
- https://www.equalexperts.com/blog/tech-focus/are-you-at-risk-from-this-critical-dbt-vulnerabilityExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-40637?
How severe is CVE-2024-40637?
How do I fix CVE-2024-40637?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40631Plate media is an open source, rich-text editor for React. E…8.1
- CVE-2024-40632Linkerd is an open source, ultralight, security-first servic…3.7
- CVE-2024-40633Sylius is an Open Source eCommerce Framework on Symfony. A s…5.3
- CVE-2024-40634Argo CD is a declarative, GitOps continuous delivery tool fo…7.5
- CVE-2024-40635containerd is an open-source container runtime. A bug was fo…7.8
- CVE-2024-40636Steeltoe is an open source project that provides a collectio…5.3
- CVE-2024-40638GLPI is a free asset and IT management software package. An …8.8
- CVE-2024-40639Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2024-4064A vulnerability was found in Tenda AC8 16.03.34.09. It has b…8.8
- CVE-2024-40640vodozemac is an open source implementation of Olm and Megolm…2.9
- CVE-2024-40641Nuclei is a fast and customizable vulnerability scanner base…7.4
- CVE-2024-40642The netty incubator codec.bhttp is a java language binary ht…8.1
Are you affected by CVE-2024-40637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
