CVE-2024-38368 is a critical vulnerability affecting trunk.cocoapods.org, the authentication server for the CocoaPods dependency manager. This flaw allowed unauthorized claiming of older, unclaimed pods or pods with all owners removed, potentially leading to supply chain attacks against iOS and macOS applications. With a CVSS score of 9.3 (CRITICAL), it presents a low-complexity attack vector (AV:N/AC:L/PR:N/UI:N) with high integrity impact (I:H) and low availability impact (A:L). Although there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness. The issue was patched server-side in September 2023.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-09-22CPE matchmatch criteria | cpe:2.3:a:cocoapods:trunk.cocoapods.org:*:*:*:*:ruby:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.