CVE-2024-35232 is a low-severity information disclosure vulnerability affecting the github.com/huandu/facebook Go package, which supports the Facebook Graph API. The vulnerability allows an access_token to be exposed in error messages during failed HTTP requests. With a CVSS score of 3.7 (Low), it requires high attack complexity and only leads to limited confidentiality impact, with no integrity or availability impact. This issue has been patched in version 2.7.2, and there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Huandu | <= 2.7.1CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.