cve/2024/CVE-2024-23738.md
2024-05-25 21:48:12 +02:00

950 B

CVE-2024-23738

Description

** DISPUTED ** An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."

POC

Reference

No PoCs from references.

Github