PT-2021-2515 · Flatpak+7 · Flatpak+7
Anton Lydike
·
Published
2021-03-02
·
Updated
2023-12-23
·
CVE-2021-21381
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Flatpak versions 0.9.4 through 1.10.2
Description
The issue is related to the "file forwarding" feature in Flatpak, which can be exploited by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. This can be achieved by putting special tokens
@@ and/or @@u in the Exec field of a Flatpak app's .desktop file, tricking Flatpak into behaving as though the user had chosen to open a target file with their Flatpak app. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.Recommendations
For Flatpak versions 0.9.4 through 1.10.2, update to version 1.10.2 to resolve the issue.
As a temporary workaround, consider avoiding installing Flatpak apps from untrusted sources, or check the contents of the exported
.desktop files in exports/share/applications/*.desktop to make sure that literal filenames do not follow @@ or @@u.
Restrict access to the vulnerable "file forwarding" feature to minimize the risk of exploitation.Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Flatpak
Linuxmint
Red Hat
Suse
Ubuntu