CVE-2024-38367 describes a critical session hijacking vulnerability in trunk.cocoapods.org, the authentication server for the CocoaPods dependency manager. This flaw allowed attackers to compromise owner sessions, leading to full takeover of CocoaPods trunk accounts and potential manipulation of pod specifications, disrupting legitimate library distribution. With a CVSS score of 9.6 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Although patched server-side in October 2023, there is no public exploit code available, nor is it listed on the CISA KEV catalog, yet it has garnered significant community discussion and media coverage, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-10-27CPE matchmatch criteria | cpe:2.3:a:cocoapods:trunk.cocoapods.org:*:*:*:*:ruby:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.