PT-2023-5599 · Tauri · Tauri

Chip-Crabnebula

+1

·

Published

2023-06-21

·

Updated

2023-07-05

·

CVE-2023-34460

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tauri versions 1.4.0
Description The issue is related to a regression in the Filesystem scope check for dotfiles on Unix systems, introduced in the 1.4.0 release. This regression affects Tauri applications using wildcard scopes in the fs endpoint, allowing implicit access to dotfiles. The problem can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Tauri version 1.4.0, update to version 1.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the fs endpoint until the update is applied.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-06254
CVE-2023-34460
GHSA-WMFF-GRCW-JCFM

Affected Products

Tauri