Exploit Report

Computer Security And Bug Information

CVE-2024-32657

CVECVE-2024-32657
CVE Title
Published Date2024-04-22T23:15Z
Modified Date2024-04-23T12:52Z
DescriptionHydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser context of Hydra and execute authenticated HTTP requests. The abused feature allows Nix builds to specify files that Hydra serves to clients. One use of this functionality is serving NixOS `.iso` files. The issue is only with html files served by Hydra. The issue has been patched on https://hydra.nixos.org around 2024-04-21 14:30 UTC. The nixpkgs package were fixed in unstable and 23.11. Users with custom Hydra packages can apply the fix commit to their local installations. The vulnerability is only triggered when opening HTML build artifacts, so not opening them until the vulnerability is fixed works around the issue.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/NixOS/hydra/security/advisories/GHSA-2p75-6g9f-pqgx
Reference Description https://github.com/NixOS/hydra/security/advisories/GHSA-2p75-6g9f-pqgx
Reference URLhttps://github.com/NixOS/nixpkgs/pull/306017
Reference Description https://github.com/NixOS/nixpkgs/pull/306017
Reference URLhttps://github.com/NixOS/nixpkgs/pull/306018
Reference Description https://github.com/NixOS/nixpkgs/pull/306018
Reference URLhttps://github.com/NixOS/hydra/commit/b72528be5074f3e62e9ae2c2ae8ef9c07a0b4dd3
Reference Description https://github.com/NixOS/hydra/commit/b72528be5074f3e62e9ae2c2ae8ef9c07a0b4dd3
Sources NIST MITRE
Note
  • No CVSS data for this CVE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles