CVE-2024-22047
published 2024-01-04CVE-2024-22047: A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user.
PriorityP411low3.1CVSS 3.1
AVNACHPRLUINSUCNILAN
EPSS
0.49%
39.1th percentile
A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| collectiveidea | audited | >= 4.0.0 < 5.3.3 | 5.3.3 |
| collectiveidea | audited | >= 4.0.0 < 5.3.3 | 5.3.3 |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
audited: race condition can lead to audit logs being incorrectly attributed to the wrong user
vendor_redhat·2024-01-04·CVSS 3.1
CVE-2024-22047 [LOW] CWE-362 audited: race condition can lead to audit logs being incorrectly attributed to the wrong user
audited: race condition can lead to audit logs being incorrectly attributed to the wrong user
A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user.
A race condition flaw was found in Audited. This issue may allow an authenticated user to attribute audit log entries to another user.
OSV
Race Condition leading to logging errors
osv·2023-05-01
CVE-2024-22047 [LOW] Race Condition leading to logging errors
Race Condition leading to logging errors
In certain setups with threaded web servers, Audited's use of `Thread.current` can incorrectly attributed audits to the wrong user.
Fixed in 5.3.3.
In March, @convisoappsec noticed that the library in question had a Race Condition problem, which caused logs to be registered at times with different users than those who performed the genuine actions.
- The first issue we identified was from November 2021: https://github.com/collectiveidea/audited/issues/601
- So the solution was implemented in the following Pull Request: https://github.com/collectiveidea/audited/pull/669
- And the feature was published in version 5.3.3: RELEASE: https://github.com/collectiveidea/audited/pull/671
GHSA
Race Condition leading to logging errors
ghsa·2023-05-01
CVE-2024-22047 [LOW] Race Condition leading to logging errors
Race Condition leading to logging errors
In certain setups with threaded web servers, Audited's use of `Thread.current` can incorrectly attributed audits to the wrong user.
Fixed in 5.3.3.
In March, @convisoappsec noticed that the library in question had a Race Condition problem, which caused logs to be registered at times with different users than those who performed the genuine actions.
- The first issue we identified was from November 2021: https://github.com/collectiveidea/audited/issues/601
- So the solution was implemented in the following Pull Request: https://github.com/collectiveidea/audited/pull/669
- And the feature was published in version 5.3.3: RELEASE: https://github.com/collectiveidea/audited/pull/671
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/advisories/GHSA-hjp3-5g2q-7jwwhttps://github.com/collectiveidea/audited/issues/601https://github.com/collectiveidea/audited/pull/669https://github.com/collectiveidea/audited/pull/671https://github.com/collectiveidea/audited/security/advisories/GHSA-hjp3-5g2q-7jwwhttps://vulncheck.com/advisories/vc-advisory-GHSA-hjp3-5g2q-7jwwhttps://github.com/advisories/GHSA-hjp3-5g2q-7jwwhttps://github.com/collectiveidea/audited/issues/601https://github.com/collectiveidea/audited/pull/669https://github.com/collectiveidea/audited/pull/671https://github.com/collectiveidea/audited/security/advisories/GHSA-hjp3-5g2q-7jwwhttps://vulncheck.com/advisories/vc-advisory-GHSA-hjp3-5g2q-7jww
2024-01-04
Published