CVE-2024-24554

Source
https://cve.org/CVERecord?id=CVE-2024-24554
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24554.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24554
Published
2024-06-24T07:11:36.377Z
Modified
2026-07-15T01:49:03.760496832Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Bludit - Insecure Token Generation
Details

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24554.json",
    "cna_assigner": "NCSC.ch",
    "cwe_ids": [
        "CWE-287",
        "CWE-338"
    ]
}
References

Affected packages

Git / github.com/bludit/bludit

Affected ranges

Type
GIT
Repo
https://github.com/bludit/bludit
Events
Database specific
{
    "cpe": "cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "3.14.0"
        },
        {
            "last_affected": "3.15.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

2.*
2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24554.json"