CVE-2024-22194 - CVE House
Back to Database
Status published Low CVE-2024-22194

cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code

Vulnerability Description

cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and since `0.5.0`, before `0.15.0`. The vulnerability stems from a Python function, `cdo_local_uuid.local_uuid()`, and its original implementation `case_utils.local_uuid()`.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-22194

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Cyber-Domain-Ontology

View all reports →

Affected Software

CDO-Utility-Local-UUID
Vulnerable Versions:
= 0.4.0, = 0.5.0, = 0.6.0, = 0.7.0, = 0.8.0, = 0.9.0, = 0.10.0, = 0.11.0, = 0.12.0

Timeline

Official Publish: January 11th, 2024
Last Modified: June 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.