CVE-2024-27916 affects lfprojects Minder, a software supply chain security platform, prior to version 0.0.33. This vulnerability allows an authenticated user to bypass access controls and retrieve information about any repository or artifact in the database, regardless of ownership or assigned permissions. Rated Medium (CVSS 4.3), the flaw has low attack complexity and requires valid user credentials, potentially leading to unauthorized information disclosure. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.33CPE matchmatch criteria | cpe:2.3:a:lfprojects:minder:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.