← Back to CVE List

CVE-2024-31455

Published: 2024-04-09T17:16Z
Last Modified: 2024-11-21T09:13Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository. This issue is patched in pull request 2941. As a workaround, revert prior to `5c381cf`, or roll forward past `2eb94e7`. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt