Low severityNVD Advisory· Published Jan 11, 2024· Updated Jun 3, 2025
cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
CVE-2024-22194
Description
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in cdo-local-uuid at version 0.4.0, and in case-utils in unpatched versions (matching the pattern 0.x.0) at and since 0.5.0, before 0.15.0. The vulnerability stems from a Python function, cdo_local_uuid.local_uuid(), and its original implementation case_utils.local_uuid().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cdo-local-uuidPyPI | >= 0.4.0, < 0.5.0 | 0.5.0 |
case-utilsPyPI | >= 0.5.0, < 0.5.1 | 0.5.1 |
case-utilsPyPI | >= 0.6.0, < 0.6.1 | 0.6.1 |
case-utilsPyPI | >= 0.7.0, < 0.7.1 | 0.7.1 |
case-utilsPyPI | >= 0.8.0, < 0.8.1 | 0.8.1 |
case-utilsPyPI | >= 0.9.0, < 0.9.1 | 0.9.1 |
case-utilsPyPI | >= 0.10.0, < 0.10.1 | 0.10.1 |
case-utilsPyPI | >= 0.11.0, < 0.11.1 | 0.11.1 |
case-utilsPyPI | >= 0.12.0, < 0.12.1 | 0.12.1 |
case-utilsPyPI | >= 0.13.0, < 0.13.1 | 0.13.1 |
case-utilsPyPI | >= 0.14.0, < 0.14.1 | 0.14.1 |
Affected products
3- ghsa-coords2 versions
>= 0.5.0, < 0.5.1+ 1 more
- (no CPE)range: >= 0.5.0, < 0.5.1
- (no CPE)range: >= 0.4.0, < 0.5.0
- Range: = 0.4.0
Patches
Vulnerability mechanics
References
18- github.com/advisories/GHSA-rgrf-6mf5-m882ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-22194ghsaADVISORY
- github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/commit/9e78f7cb1075728d0aafc918514f32a1392cd235ghsax_refsource_MISCWEB
- github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/3ghsax_refsource_MISCWEB
- github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/pull/4ghsax_refsource_MISCWEB
- github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID/security/advisories/GHSA-rgrf-6mf5-m882ghsax_refsource_CONFIRMWEB
- github.com/casework/CASE-Utilities-Python/commit/00864cd12de7c50d882dd1a74915d32e939c25f9ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/1cccae8eb3cf94b3a28f6490efa0fbf5c82ebd6bghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/5acb929dfb599709d1c8c90d1824dd79e0fd9e10ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/7e02d18383eabbeb9fb4ec97d81438c9980a4790ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/80551f49241c874c7c50e14abe05c5017630dad2ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/939775f956796d0432ecabbf62782ed7ad1007b5ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/db428a0745dac4fdd888ced9c52f617695519f9dghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/e4ffadc3d56fd303b8f465d727c4a58213d311a1ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/fca7388f09feccd3b9ea88e6df9c7a43a5349452ghsax_refsource_MISCWEB
- github.com/casework/CASE-Utilities-Python/commit/fdc32414eccfcbde6be0fd91b7f491cc0779b02dghsax_refsource_MISCWEB
- github.com/pypa/advisory-database/tree/main/vulns/case-utils/PYSEC-2024-5.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/cdo-local-uuid/PYSEC-2024-6.yamlghsaWEB
News mentions
0No linked articles in our index yet.