CVE-2024-25626

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-25626
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-25626.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-25626
Aliases
  • GHSA-75xw-78mm-72r4
Published
2024-02-19T19:31:37.398Z
Modified
2025-11-30T11:31:28.139198Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Yocto Project Security Advisory - BitBake/Toaster
Details

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows an attacker to perform a remote code execution in the server's shell via a crafted HTTP request. Authentication is not necessary. Toaster server execution has to be specifically run and is not the default for Bitbake command line builds, it is only used for the Toaster web based user interface to Bitbake. The fix has been backported to the bitbake included with Yocto Project 5.0, 3.1.31, 4.0.16, and 4.3.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25626.json",
    "cwe_ids": [
        "CWE-78"
    ]
}
References

Affected packages

Git / github.com/yoctoproject/poky

Affected ranges

Type
GIT
Repo
https://github.com/yoctoproject/poky
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.1_M1.rc1
1.1_M2.rc1
1.1_M2.rc2
1.1_M3.rc2
1.1_M4.rc2+
1.1_M4.rc3
1.2_M2
1.2_M2.final
1.2_M2.rc1
1.2_M3
1.2_M3.final
1.2_M3.rc1
1.2_M4.rc1
1.2_M4.rc2
1.2_M4.rc3
1.2_M4.rc3.1
1.2_M4.rc3.2
1.2_M4.rc4
1.3_M1
1.3_M1.final
1.3_M1.rc1
1.3_M2.rc1
1.3_M3
1.3_M3.final
1.3_M3.rc2
1.3_M4.rc1
1.3_M5.rc1
1.3_M5.rc2
1.4_M1
1.4_M1.final
1.4_M1.rc1
1.4_M3.rc1
1.4_M4
1.4_M4.final
1.4_M4.rc1
1.4_M5
1.4_M5.final
1.4_M5.rc1
1.4_M5.rc2
1.4_M5.rc3
1.5_M1.final
1.5_M1.rc1
1.5_M2.rc1
1.5_M3
1.5_M3.final
1.5_M3.rc1
1.5_M4
1.5_M4.final
1.5_M4.rc1
1.5_M4.rc2
1.5_M4.rc3
1.5_M5.rc1
1.5_M5.rc2
1.5_M5.rc3
1.5_M5.rc4
1.5_M5.rc5
1.5_M5.rc6
1.5_M5.rc7
1.5_M5.rc8
1.6_M1
1.6_M1.final
1.6_M1.rc1
1.6_M2
1.6_M3
1.6_M3.final
1.6_M4
1.7_M1
1.7_M2
1.7_M3
1.8_M1
1.8_M2
1.8_M3
1.9_M2

2.*

2.1_M1
2.2_M1
2.2_M2
2.2_M3
2.3_M1
2.3_M2
2.3_M3
2.4_M1
2.4_M2
2.4_M3
2.5_M1
2.5_M2
2.5_M3
2.6_M1
2.6_M2
2.6_M3
2.7_M1
2.7_M2
2.7_M3
2.8_M1
2.8_M2
2.8_M3

3.*

3.1_M1
3.1_M2
3.1_M3

bernard-5.*

bernard-5.0-alpha

dora-10.*

dora-10.0.0
dora-10.0.0.final

dunfell-23.*

dunfell-23.0.0
dunfell-23.0.1
dunfell-23.0.10
dunfell-23.0.11
dunfell-23.0.12
dunfell-23.0.13
dunfell-23.0.14
dunfell-23.0.15
dunfell-23.0.16
dunfell-23.0.17
dunfell-23.0.18
dunfell-23.0.19
dunfell-23.0.2
dunfell-23.0.20
dunfell-23.0.21
dunfell-23.0.22
dunfell-23.0.23
dunfell-23.0.24
dunfell-23.0.25
dunfell-23.0.26
dunfell-23.0.27
dunfell-23.0.28
dunfell-23.0.29
dunfell-23.0.3
dunfell-23.0.30
dunfell-23.0.4
dunfell-23.0.5
dunfell-23.0.6
dunfell-23.0.7
dunfell-23.0.8
dunfell-23.0.9

jethro-14.*

jethro-14.0.0

krogoth-15.*

krogoth-15.0.0

poky-10.*

poky-10.0.0.final

pyro-17.*

pyro-17.0.0

rocko-18.*

rocko-18.0.0

sumo-19.*

sumo-19.0.0

thud-20.*

thud-20.0.0

uninative-1.*

uninative-1.0
uninative-1.3
uninative-1.4
uninative-1.5
uninative-1.6
uninative-1.7
uninative-1.8
uninative-1.9

uninative-2.*

uninative-2.0
uninative-2.1
uninative-2.2
uninative-2.3
uninative-2.4
uninative-2.5
uninative-2.6
uninative-2.7
uninative-2.8

yocto-1.*

yocto-1.5
yocto-1.5.final
yocto-1.5_M5.rc2
yocto-1.9_M1

yocto-2.*

yocto-2.0
yocto-2.1
yocto-2.3
yocto-2.4
yocto-2.5
yocto-2.6

yocto-3.*

yocto-3.0
yocto-3.1
yocto-3.1.1
yocto-3.1.10
yocto-3.1.11
yocto-3.1.12
yocto-3.1.13
yocto-3.1.14
yocto-3.1.15
yocto-3.1.16
yocto-3.1.17
yocto-3.1.18
yocto-3.1.19
yocto-3.1.2
yocto-3.1.20
yocto-3.1.21
yocto-3.1.22
yocto-3.1.23
yocto-3.1.24
yocto-3.1.25
yocto-3.1.26
yocto-3.1.27
yocto-3.1.28
yocto-3.1.29
yocto-3.1.3
yocto-3.1.30
yocto-3.1.4
yocto-3.1.5
yocto-3.1.6
yocto-3.1.7
yocto-3.1.8
yocto-3.1.9

zeus-22.*

zeus-22.0.0