Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/firebase/firebase-tools: CVE-2024-4128 #2808

Open
GoVulnBot opened this issue May 2, 2024 · 0 comments
Assignees
Labels

Comments

@GoVulnBot
Copy link

CVE-2024-4128 references github.com/firebase/firebase-tools, which may be a Go module.

Description:
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit  068a2b08dc308c7ab4b569617f5fc8821237e3a0 firebase/firebase-tools@068a2b0

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/firebase/firebase-tools
      vulnerable_at: 13.8.0+incompatible
      packages:
        - package: firebase-tools
summary: CVE-2024-4128 in github.com/firebase/firebase-tools
cves:
    - CVE-2024-4128
references:
    - fix: https://github.com/firebase/firebase-tools/pull/6944
    - fix: https://github.com/firebase/firebase-tools/commit/068a2b08dc308c7ab4b569617f5fc8821237e3a0
source:
    id: CVE-2024-4128

@tatianab tatianab self-assigned this May 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants