CVE-2024-23741: Code Injection
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hyper (macOS)to a version that resolves this vulnerability.Fixed in 3.4.1 - Configuration
If affected, do not enable the RunAsNode setting; arbitrary code execution is possible via this setting in Hyper on macOS versions 3.4.1 and before.
Hyper RunAsNode = disable/avoid enabling - Configuration
If affected, do not enable the enableNodeClilnspectArguments setting; arbitrary code execution is possible via this setting in Hyper on macOS versions 3.4.1 and before.
Hyper enableNodeClilnspectArguments = disable/avoid enabling
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23741?
CVE-2024-23741 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2024-23741?
To mitigate CVE-2024-23741, upgrade Hyper to version 3.4.2 or later, which addresses this vulnerability.
Which versions of Hyper are affected by CVE-2024-23741?
CVE-2024-23741 affects Hyper versions 3.4.1 and earlier on macOS.
What can attackers do exploiting CVE-2024-23741?
Exploiting CVE-2024-23741 allows remote attackers to execute arbitrary code on affected systems.
Is there a workaround for CVE-2024-23741?
As a temporary measure, disable the RunAsNode and enableNodeClilnspectArguments settings in the configuration until the software can be updated.