CVE-2024-39314

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39314
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39314.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39314
Related
  • GHSA-q8g2-c3x5-gp89
Published
2024-07-01T22:15:03Z
Modified
2025-01-15T05:14:58.235522Z
Summary
[none]
Details

toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command line parameter. The problem was patched in version 0.5.0. As a workaround, pass --read-bearer-token-from-stdin to the launch arguments and feed the token from the standard input in version 0.4.14 or later. Earlier versions do not have this workaround.

References

Affected packages

Git / github.com/kisaragieffective/toy-blog

Affected ranges

Type
GIT
Repo
https://github.com/kisaragieffective/toy-blog
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

0.*

0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9