PT-2022-24815 · Tauri · Tauri

Martin-Ocasek

·

Published

2022-08-07

·

Updated

2022-09-21

·

CVE-2022-39215

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tauri versions prior to 1.0.6
Description Due to missing canonicalization when readDir is called recursively, it was possible to display directory listings outside of the defined fs scope. This required a crafted symbolic link or junction folder inside an allowed path of the fs scope. No arbitrary file content could be leaked.
Recommendations For versions prior to 1.0.6, upgrade to version 1.0.6 or later. As a temporary workaround for users unable to upgrade, disable the readDir endpoint in the allowlist inside the tauri.conf.json.

Exploit

Fix

Link Following

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-39215
GHSA-28M8-9J7V-X499
RUSTSEC-2022-0088

Affected Products

Tauri