PT-2021-2515 · Flatpak+7 · Flatpak+7

Anton Lydike

·

Published

2021-03-02

·

Updated

2023-12-23

·

CVE-2021-21381

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Flatpak versions 0.9.4 through 1.10.2
Description The issue is related to the "file forwarding" feature in Flatpak, which can be exploited by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. This can be achieved by putting special tokens @@ and/or @@u in the Exec field of a Flatpak app's .desktop file, tricking Flatpak into behaving as though the user had chosen to open a target file with their Flatpak app. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Flatpak versions 0.9.4 through 1.10.2, update to version 1.10.2 to resolve the issue. As a temporary workaround, consider avoiding installing Flatpak apps from untrusted sources, or check the contents of the exported .desktop files in exports/share/applications/*.desktop to make sure that literal filenames do not follow @@ or @@u. Restrict access to the vulnerable "file forwarding" feature to minimize the risk of exploitation.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1471
BDU:2021-01908
CESA-2021_1002
CESA-2021_1068
CVE-2021-21381
DSA-4868-1
GHSA-XGH4-387P-HQPP
MGASA-2021-0143
MGASA-2021-0145
OESA-2021-1149
RHSA-2021:1002
RHSA-2021:1068
RHSA-2021:1073
RHSA-2021:1074
RHSA-2021_1002
RHSA-2021_1068
SUSE-SU-2022:2990-1
USN-4951-1

Affected Products

Alt Linux
Astra Linux
Centos
Flatpak
Linuxmint
Red Hat
Suse
Ubuntu