CVE-2024-42370: Litestar has an environment Variable injection in `docs-preview.yml` workflow
Litestar’s docs-preview.yml
workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation.
References
- github.com/advisories/GHSA-4hq2-rpgc-r8r7
- github.com/litestar-org/litestar
- github.com/litestar-org/litestar/blob/ffaf5616b19f6f0f4128209c8b49dbcb41568aa2/.github/workflows/docs-preview.yml
- github.com/litestar-org/litestar/commit/84d351e96aaa2a1338006d6e7221eded161f517b
- github.com/litestar-org/litestar/security/advisories/GHSA-4hq2-rpgc-r8r7
- nvd.nist.gov/vuln/detail/CVE-2024-42370
Detect and mitigate CVE-2024-42370 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →