PT-2022-27785 · Tauri · Tauri

Lucasfernog

·

Published

2022-12-22

·

Updated

2023-01-04

·

CVE-2022-46171

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tauri versions prior to the latest release Tauri versions 1.x prior to the backported patch
Description The filesystem glob pattern wildcards *, ?, and [...] match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As ** allows for sub directories, the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches.
Recommendations For Tauri versions prior to the latest release, update to the latest release to resolve the issue. For Tauri versions 1.x, apply the backported patch to resolve the issue. As a temporary workaround, consider restricting the use of the *, ?, and [...] glob patterns in fs scopes to minimize the risk of exploitation. Avoid using the dialog.open component with the recursive option set to false until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-46171
GHSA-6MV3-WM7J-H4W5

Affected Products

Tauri