Products
Nix
- 2.22.1
Source
cve@mitre.org
Tags
CVE-2024-36050 details
Published : May 18, 2024, 10:15 p.m.
Last Modified : May 18, 2024, 10:15 p.m.
Last Modified : May 18, 2024, 10:15 p.m.
Description
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://github.com/NixOS/nix/issues/969 | cve@mitre.org |
https://github.com/NixOS/ofborg/issues/68#issuecomment-2082789441 | cve@mitre.org |
This website uses the NVD API, but is not approved or certified by it.