CVE-2024-22194: Lfprojects Case Python Utilities
Low severity, CVSS 2.8. EPSS: 0.4% chance of exploitation in the next 30 days.
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and since `0.5.0`, before `0.15.0`. The vulnerability stems from a Python function, `cdo_local_uuid.local_uuid()`, and its original implementation `case_utils.local_uuid()`.
Affected products
- Lfprojects Case Python Utilities: version 0.5.0 only; version 0.6.0 only; version 0.7.0 only; version 0.8.0 only; version 0.9.0 only; version 0.10.0 only; …
- Lfprojects Cdo Local Uuid Utility: version 0.4.0 only
Published 2024-01-11. Last modified 2026-06-17.