CVE-2022-39215: The readDir Endpoint Scope can be Bypassed With Symbolic Links in Tauri
Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when readDir is called recursively, it was possible to display directory listings outside of the defined fs scope. This required a crafted symbolic link or junction folder inside an allowed path of the fs scope. No arbitrary file content could be leaked. The issue has been resolved in version 1.0.6 and the implementation now properly checks if the requested (sub) directory is a symbolic link outside of the defined scope. Users are advised to upgrade. Users unable to upgrade should disable the readDir endpoint in the allowlist inside the tauri.conf.json.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-39215?
CVE-2022-39215 is a vulnerability in the Tauri framework that allows for the display of directory listings outside of the defined fs scope.
What is the severity of CVE-2022-39215?
The severity of CVE-2022-39215 is high with a CVSS score of 5.8.
How does CVE-2022-39215 affect Tauri?
CVE-2022-39215 affects Tauri versions up to and excluding 1.0.6.
How can I fix CVE-2022-39215?
To fix CVE-2022-39215, update Tauri to a version beyond 1.0.6.
Where can I find more information about CVE-2022-39215?
You can find more information about CVE-2022-39215 on the Tauri GitHub repository: https://github.com/tauri-apps/tauri/issues/4882