CVE-2024-27092

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27092
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27092.json
Aliases
  • GHSA-8r6h-8r68-q3pp
Published
2024-02-29T01:44:19Z
Modified
2024-03-02T20:26:57.537471Z
Details

Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easier to achieve own goals by malicious actors. This issue is fixed in 2023.12.6.

References

Affected packages

Git / github.com/hoppscotch/hoppscotch

Affected ranges

Type
GIT
Repo
https://github.com/hoppscotch/hoppscotch
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

2023.*

2023.12.0
2023.12.1
2023.12.2
2023.12.3
2023.12.4
2023.12.5
2023.4.0
2023.4.1
2023.4.2
2023.4.3
2023.4.4
2023.4.5
2023.4.6
2023.4.7
2023.4.8
2023.8.0
2023.8.1
2023.8.2
2023.8.3
2023.8.4

v0.*

v0.1.0

v1.*

v1.0.0
v1.10.0
v1.12.0
v1.5.0
v1.8.0
v1.9.0
v1.9.5
v1.9.7
v1.9.9

v2.*

v2.0.0
v2.1.0
v2.2.0
v2.2.1

v3.*

v3.0.0
v3.0.1