NA

CVE-2024-23738

Published: 28/01/2024 Updated: 11/04/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue in Postman version 10.22 and before on macOS allows a remote malicious user to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."

Vulnerable Product Search on Vulmon Subscribe to Product

postman postman

Github Repositories

CVE-2024-23738

CVE-2024-23738 An issue in Postman through 1022 on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings There is a tool designed to automate the process of searching for vulnerabilities in electron: githubcom/r3ggi/electroniz3r With this tool, we can check if the App is Vulnerable: After validation,