CVE-2024-31455 impacts Minder by Stacklok, an open-source software supply chain security platform. A SQL query error introduced during a refactoring allowed for the retrieval of a random GitHub repository when attempting to list registered repositories for a project without specifying a provider, potentially leading to unintended information disclosure. This vulnerability is rated Medium severity (CVSS 4.3), indicating a low attack complexity and requiring low privileges to exploit, with a potential impact of limited confidentiality loss. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Stacklok | Minder | = 0.0.39CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.