CRITICAL🇵🇱 Wersja polska

CVE-2024-38368

CVSS 9.3v3.1pub. 2024-07-01upd. 2024-11-21

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also possible to have all owners removed from a pod, and that made the pod available for the same claiming system. This was patched server-side in commit 71be5440906b6bdfbc0bcc7f8a9fec33367ea0f4 in September 2023.

🤖 AI Analysis
How it works

Older packages migrated before 2014 from a pull request-based workflow to the trunk system could remain in an unassigned state. If no owner ever claimed a given pod, the claiming mechanism remained active and available to any user. Additionally, it was possible to remove all owners from a package, which automatically returned it to the pool available for takeover. An attacker could then claim such a package and gain full control over its distribution.

Impact

Attackers could take over ownership of popular packages and publish malicious updates, leading to a supply chain attack and potential compromise of iOS/macOS applications using infected dependencies.

Mitigation & patch

The vulnerability was fixed on the server side in commit 71be5440906b6bdfbc0bcc7f8a9fec33367ea0f4 in September 2023. CocoaPods package owners should ensure that their pods have at least one current owner assigned. It is recommended to review owned packages according to guidelines available at blog.cocoapods.org/Claim-Your-Pods

Who is affected

Server trunk.cocoapods.org — affects packages (pods) migrated from the older workflow (pre-2014) that were never claimed by an owner or that lost all owners

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
  • Cocoapods Trunk.cocoapods.org

    APP
    Cocoapods
    < 2023-09-22
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38366CRITICAL10.0PL ✓same product

RCE z uprawnieniami root w serwerze trunk.cocoapods.org

CVE-2024-38367HIGH8.2same product

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66...

CVE-2022-21223HIGH8.1same vendor

The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. W...

CVE-2022-24440HIGH8.1same vendor

The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection...