CVE-2024-25129: Limited data exfiltration in CodeQL CLI

Published Feb 22, 2024
·
Updated

The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable version of the CLI is used to process either a maliciously modified CodeQL database, or a specially prepared set of QL query sources, the CLI can be made to make an outgoing HTTP request to an URL that contains material read from a local file chosen by the attacker. This may result in a loss of privacy of exfiltration of secrets. Security researchers and QL authors who receive databases or QL source files from untrusted sources may be impacted. A single untrusted .ql or .qll file cannot be affected, but a zip archive or tarball containing QL sources may unpack auxiliary files that will trigger an attack when CodeQL sees them in the file system. Those using CodeQL for routine analysis of source trees with a preselected set of trusted queries are not affected. In particular, extracting XML files from a source tree into the CodeQL database does not make one vulnerable. The problem is fixed in release 2.16.3 of the CodeQL CLI. Other than upgrading, workarounds include not accepting CodeQL databases or queries from untrusted sources, or only processing such material on a machine without an Internet connection. Customers who use older releases of CodeQL for security scanning in an automated CI system and cannot upgrade for compliance reasons can continue using that version. That use case is safe. If such customers have a private query pack and use the codeql pack create command to precompile them before using them in the CI system, they should be using the production CodeQL release to run codeql pack create. That command is safe as long as the QL source it precompiled is trusted. All other development of the query pack should use an upgraded CLI.

Affected Software

2 affected components
GitHub CodeQL CLI<2.16.3
GitHub CodeQL CLI<2.16.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade CodeQL CLI to a version that resolves this vulnerability.

    Fixed in 2.16.3
  2. Configuration

    When precompiling a private query pack with the `codeql pack create` command (for use in an automated CI system), run `codeql pack create` using the production CodeQL release (safe as long as the QL source it precompiles is trusted).

    codeql pack create use = production CodeQL release
  3. Compensating control

    Do not accept CodeQL databases or QL queries from untrusted sources; alternatively, only process such material on a machine without an Internet connection.

  4. Operational

    If you previously processed maliciously modified CodeQL databases or specially prepared QL query sources using a vulnerable CodeQL CLI, assume limited data exfiltration of secrets may have occurred; rotate any exposed secrets/credentials.

Event History

Feb 22, 2024
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-25129?

CVE-2024-25129 has been classified with a medium severity due to its potential impact on XML External Entity attacks.

2

How do I fix CVE-2024-25129?

To fix CVE-2024-25129, update to CodeQL CLI version 2.16.3 or later.

3

What software is affected by CVE-2024-25129?

CVE-2024-25129 affects versions of GitHub CodeQL CLI prior to 2.16.3.

4

What kind of attack does CVE-2024-25129 facilitate?

CVE-2024-25129 facilitates an XML External Entity (XXE) attack on the CodeQL CLI.

5

What is the impact of exploiting CVE-2024-25129?

Exploiting CVE-2024-25129 could allow an attacker to access sensitive files and potentially execute arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203