A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.
History

Mon, 18 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Gnome Maps
Gnome Maps gnome Maps
CPEs cpe:2.3:a:gnome_maps:gnome_maps:*:*:*:*:*:*:*:*
Vendors & Products Gnome Maps
Gnome Maps gnome Maps
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 17 Nov 2024 12:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.
Title Gnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss) via its service.json
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-11-17T12:25:49.293Z

Updated: 2024-11-18T16:39:41.368Z

Reserved: 2023-09-15T07:17:59.706Z

Link: CVE-2023-43091

cve-icon Vulnrichment

Updated: 2024-11-18T16:39:32.012Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-17T13:15:14.140

Modified: 2024-11-18T17:11:17.393

Link: CVE-2023-43091

cve-icon Redhat

No data.