CVE-2023-43091: Gnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss) via its service.json
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.
Other sources
GNOME Maps is vulnerable to a code injection attack (similar to XSS) via its service.json configuration file downloaded from https://static.gnome.org/gis.gnome.org/v1/service.json. If the configuration file is malicious, it may execute arbitrary code.
Affected versions: 43 prior to 43.7, 44 prior to 44.4
Discoverer/Credit: Michael Evans
References, additional information: https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588 https://gitlab.gnome.org/GNOME/gnome-maps/-/commit/d26cd774d524404ef7784e6808f551de83de4bea
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43091?
CVE-2023-43091 is classified as a medium severity vulnerability due to its potential for arbitrary code execution via a malicious configuration file.
How do I fix CVE-2023-43091?
To fix CVE-2023-43091, upgrade GNOME Maps to version 44.6 or later to ensure the code injection vulnerability is patched.
Which versions of GNOME Maps are affected by CVE-2023-43091?
CVE-2023-43091 affects GNOME Maps versions prior to 44.6, including version 44.5 and earlier versions such as 43.0 to 44.4.
What type of attack is associated with CVE-2023-43091?
CVE-2023-43091 is associated with a code injection attack that can execute arbitrary code through the service.json configuration file.
Is there a workaround for CVE-2023-43091?
Currently, the best resolution for CVE-2023-43091 is to update GNOME Maps to the latest version, as there are no established workarounds for this vulnerability.