PT-2023-28991 · Altair · Altair
Masood
·
Published
2023-10-04
·
Updated
2023-10-10
·
CVE-2023-43799
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Altair versions prior to 5.2.5
Description
The Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system and does not isolate the context of the renderer process. This issue affects versions of the software running on MacOS, Windows, and Linux.
Recommendations
For versions prior to 5.2.5, update to version 5.2.5 to resolve the issue. As a temporary workaround, consider restricting access to external URLs and isolating the renderer process context until the update is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Altair