CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.2epss 0.1%
probabilidade de exploração
0.1%top 97% das CVEs
exploração observada
nãonenhuma fonte reporta
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the same host can read the App Store Connect API key written to a fixed path, pre-create files or symbolic links at predictable locations to redirect writes to attacker-controlled destinations, or tamper with notarization archives before submission.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
steipete · CodexBarReferências
https://github.com/steipete/CodexBar/commit/e7d932616508cee43ea9bcc63c269b14698de655https://github.com/steipete/CodexBar/pull/1228https://github.com/steipete/CodexBar/releases/tag/v0.32.0https://www.vulncheck.com/advisories/codexbar-insecure-temporary-file-handling-in-notarization-workflow