buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2024-23770
Component Overview
Vulnerability Overview
Name
CVE-2024-23770
Source
NVD (
link
)
Debian (
link
)
Description
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
CWEs
Published Date
Jan 22, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2024/01/25/1
Mailing List
https://github.com/emikulic/darkhttpd/commit/2b339828b2a42a5fda105ea84934957a7d23e35d
Patch
https://github.com/emikulic/darkhttpd/compare/v1.14...v1.15
Patch
http://www.openwall.com/lists/oss-security/2024/01/25/1
Mailing List
https://github.com/emikulic/darkhttpd/commit/2b339828b2a42a5fda105ea84934957a7d23e35d
Patch
https://github.com/emikulic/darkhttpd/compare/v1.14...v1.15
Patch
Analysis
#
Affected Component
Analysis
darkhttpd
Exploitable
Vulnerability Ratings
#
5.5
CVSSv31
5.5
CVSSv31
NaN
other
Others affected component
#
Name
Project
Project Version
Version
Status
darkhttpd
buildroot
master
1.17
Not Affected