PT-2023-5599 · Tauri · Tauri

Chip-Crabnebula

+1

·

Publicado

2023-06-21

·

Atualizado

2023-07-05

·

CVE-2023-34460

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tauri versions 1.4.0
Description The issue is related to a regression in the Filesystem scope check for dotfiles on Unix systems, introduced in the 1.4.0 release. This regression affects Tauri applications using wildcard scopes in the fs endpoint, allowing implicit access to dotfiles. The problem can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Tauri version 1.4.0, update to version 1.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the fs endpoint until the update is applied.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06254
CVE-2023-34460
GHSA-WMFF-GRCW-JCFM

Produtos afetados

Tauri