CVE-2024-54147

Source
https://cve.org/CVERecord?id=CVE-2024-54147
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-54147.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-54147
Aliases
  • GHSA-8v9h-hxp5-9jcx
Published
2024-12-09T18:55:58.277Z
Modified
2026-04-10T05:18:28.572616Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Altair GraphQL Client's desktop app does not validate HTTPS certificates
Details

Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL request and response headers and bodies fully compromised including authorization tokens. The attack also allows obtaining full access to any signed-in Altair GraphQL Cloud account and replacing payment checkout pages with a malicious website. Version 8.0.5 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-295"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/54xxx/CVE-2024-54147.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/altair-graphql/altair

Affected ranges

Type
GIT
Repo
https://github.com/altair-graphql/altair
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.0.5"
        }
    ]
}

Affected versions

v1.*
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.1.1
v1.1.2
v1.2.1
v4.*
v4.2.0
v4.2.1
v4.2.2
v4.3.0
v4.3.1
v4.4.0
v4.4.1
v4.4.2
v4.5.0
v4.5.1
v4.5.2
v4.5.3
v4.6.0
v4.6.2
v4.6.3
v4.6.4
v5.*
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.16
v5.0.17
v5.0.18
v5.0.19
v5.0.2
v5.0.20
v5.0.21
v5.0.22
v5.0.23
v5.0.24
v5.0.25
v5.0.26
v5.0.27
v5.0.28
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.2.1
v5.2.10
v5.2.11
v5.2.12
v5.2.13
v5.2.14
v5.2.2
v5.2.3
v5.2.4
v5.2.5
v5.2.6
v5.2.7
v5.2.8
v5.2.9
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.1.0
v6.2.0
v6.3.0
v6.3.1
v6.4.0
v6.4.1
v6.4.2
v7.*
v7.0.0
v7.0.1
v7.1.0
v7.2.0
v7.2.1
v7.2.2
v7.2.3
v7.2.4
v7.3.0
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v8.*
v8.0.0
v8.0.1
v8.0.2
v8.0.3
v8.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-54147.json"