CVE-2024-38366
published 2024-07-01CVE-2024-38366: trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email…
PriorityP179critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
17.79%
96.8th percentile
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on signup used a rfc-822 library which executes a shell command to validate the email domain MX records validity. It works via an DNS MX. This lookup could be manipulated to also execute a command on the trunk server, effectively giving root access to the server and the infrastructure. This issue was patched server-side with commit 001cc3a430e75a16307f5fd6cdff1363ad2f40f3 in September 2023. This RCE triggered a full user-session reset, as an attacker could have used this method to write to any Podspec in trunk.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cocoapods | cocoapods | < 001cc3a430e75a16307f5fd6cdff1363ad2f40f3 | 001cc3a430e75a16307f5fd6cdff1363ad2f40f3 |
| cocoapods | trunk.cocoapods.org | < 2023-09-22 | 2023-09-22 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
https://blog.cocoapods.org/CocoaPods-Trunk-RCEs-2023https://evasec.webflow.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods#2-remote-code-execution-on-the-cocoapods-trunk-serverhttps://github.com/CocoaPods/CocoaPods/security/advisories/GHSA-x2x4-g675-qg7chttps://blog.cocoapods.org/CocoaPods-Trunk-RCEs-2023https://evasec.webflow.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods#2-remote-code-execution-on-the-cocoapods-trunk-serverhttps://github.com/CocoaPods/CocoaPods/security/advisories/GHSA-x2x4-g675-qg7c
2024-07-01
Published