First published: Wed Oct 23 2024(Updated: )
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.
Credit: report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
npm/snyk-gradle-plugin | <4.5.0 | 4.5.0 |
Snyk Snyk Cli | <1.1294.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48964 has been classified as a code injection vulnerability that can have significant security implications.
To fix CVE-2024-48964, update the Snyk CLI to versions greater than 1.1294.0.
CVE-2024-48964 affects Snyk CLI versions up to 1.1294.0 and the snyk-gradle-plugin versions below 4.5.0.
CVE-2024-48964 can be exploited when Snyk test is run inside an untrusted Gradle project.
Using Snyk CLI prior to version 1.1294.0 is not safe, especially when scanning untrusted projects.