2024-12-22 03:03:49 +00:00

72 lines
2.6 KiB
JSON

{
"id": "CVE-2024-56083",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-12-16T03:15:04.650",
"lastModified": "2024-12-16T17:15:13.883",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific \"Use Devin's Machine\" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin session to social media, or publicly streams their Devin session."
},
{
"lang": "es",
"value": "La versi\u00f3n anterior a 2024-12-12 de Cognition Devin proporciona acceso de escritura al c\u00f3digo a un atacante que descubre la URL https://vscode-randomly_generated_string.devinapps.com (tambi\u00e9n conocida como la URL de uso compartido en vivo de VSCode) para una sesi\u00f3n espec\u00edfica de \"Use Devin's Machine\". Por ejemplo, esta URL se puede descubrir si un cliente publica una captura de pantalla de una sesi\u00f3n de Devin en las redes sociales o transmite p\u00fablicamente su sesi\u00f3n de Devin."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"references": [
{
"url": "https://news.ycombinator.com/item?id=42420423",
"source": "cve@mitre.org"
},
{
"url": "https://trust.cognition.ai",
"source": "cve@mitre.org"
},
{
"url": "https://www.youtube.com/watch?v=927W6zzvV-c",
"source": "cve@mitre.org"
},
{
"url": "https://x.com/cognition_labs/status/1867351521035530698",
"source": "cve@mitre.org"
}
]
}