Vulnerability Description
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snyk | Snyk Cli | < 1.1294.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-48964?
CVE-2024-48964 is a vulnerability with a CVSS score of 7.5 (HIGH). The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due ...
How severe is CVE-2024-48964?
CVE-2024-48964 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48964?
Check the references section above for vendor advisories and patch information. Affected products include: Snyk Snyk Cli.