CVE-2024-45798: Multiple Poisoned Pipeline Execution (PPE) vulnerabilities
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The arduino-esp32 CI is vulnerable to multiple Poisoned Pipeline Execution (PPE) vulnerabilities. Code injection in testsresults.yml workflow (GHSL-2024-169) and environment Variable injection (GHSL-2024-170). These issue have been addressed but users are advised to verify the contents of the downloaded artifacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45798?
CVE-2024-45798 is classified as a critical vulnerability due to its potential for code injection.
How do I fix CVE-2024-45798?
To address CVE-2024-45798, update to the latest version of arduino-esp32 that includes fixes for the Poisoned Pipeline Execution vulnerabilities.
What are the main vulnerabilities described in CVE-2024-45798?
CVE-2024-45798 involves multiple Poisoned Pipeline Execution (PPE) vulnerabilities that could allow code injection.
Which versions of arduino-esp32 are affected by CVE-2024-45798?
CVE-2024-45798 affects all versions of arduino-esp32 that utilize the compromised tests_results.yml workflow.
Is CVE-2024-45798 a known exploitation vector?
Yes, CVE-2024-45798's exploitation vector primarily revolves around code injection vulnerabilities identified in the GitHub Actions workflows.