PT-2022-15033 · Flatpak+7 · Flatpak+7

Mcv

·

Published

2022-01-13

·

Updated

2024-06-15

·

CVE-2022-21682

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Flatpak versions prior to 1.12.3 and 1.10.6
Description A path traversal issue affects Flatpak, a Linux application sandboxing and distribution framework. The flatpak-builder applies finish-args last in the build, granting the build directory full access as specified in the manifest. Normally, this is not a problem, but if --mirror-screenshots-url is specified, flatpak-builder launches flatpak build --nofilesystem=host appstream-utils mirror-screenshots after finalization, potentially leading to issues. In normal use, empty directories can be created wherever the user has write permissions. However, a malicious application could replace the appstream-util binary and potentially do something more hostile.
Recommendations For versions prior to 1.12.3, update to version 1.12.3 or later. For versions prior to 1.10.6, update to version 1.10.6 or later. As a temporary workaround, consider avoiding the use of the --mirror-screenshots-url option until the issue is resolved. Restrict access to the appstream-util binary to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7458
ALSA-2022_7458
ALT-PU-2022-1080
ALT-PU-2022-1081
ALT-PU-2022-1126
ALT-PU-2022-1127
CESA-2022_7458
CVE-2022-21682
DSA-5049-1
GHSA-8CH7-5J3H-G4FX
MGASA-2022-0131
OESA-2022-1788
OPENSUSE-SU-2022:0712-1
OPENSUSE-SU-2022_0712-1
OPENSUSE-SU-2024:11755-1
OPENSUSE-SU-2024:11756-1
RHSA-2022:7458
RHSA-2022_7458
RLSA-2022:7458
SUSE-SU-2022:0712-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Flatpak
Red Hat
Rocky Linux
Suse