CVE-2024-48964 - CVE House
Back to Database
Status published High CVE-2024-48964

The package Snyk CLI before 1.1294.0 is vulnerable to Code...

Vulnerability Description

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-48964

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Snyk Cli, Snyk Gradle Plugin
Vulnerable Versions:
0

Timeline

Official Publish: October 23rd, 2024
Last Modified: October 24th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)