Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.4epss 0.3%
probabilidad de explotación
0.3%top 81% de las CVE
explotación observada
noninguna fuente lo reporta
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
Productos afectados
triggerdotdev · trigger.devReferencias
https://github.com/triggerdotdev/trigger.devhttps://github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254https://github.com/triggerdotdev/trigger.dev/issues/4173https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jvhttps://www.vulncheck.com/advisories/trigger-dev-before-4.5.2-unauthorized-environment-access-via-run-replay