REDHAT-BUG-2542628: Low severity Flatpak Flatpak vulnerability
GHSA-7rvf-rqr3-43j4 (https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4)
Description: When downloading apps or runtimes from an OCI repository that requires authentication, the OCI authentication token is written with the default permissions 0644. On multi-user systems this allows other local users to read the token file. This is related to GHSA-r9w3-qx54-qvc8 but with a different impact: unlike that issue, this one is not mitigated by a restrictive umask. libostree repositories such as Flathub are not affected; this only applies to apps, runtimes, or extensions downloaded from an OCI repository (such as those used by Fedora).
Mitigation: No known mitigation other than updating, or using libostree repositories (e.g. Flathub) or unauthenticated/public OCI repositories instead. Patched in 1.18.4 by commit f911bbf0 ("oci: Stop persisting bearer token to child repo on disk"). Credit: Found by AISLE in cooperation with Red Hat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.18.4Patch f911bbf0 - Compensating control
Use libostree repositories such as Flathub, or unauthenticated/public OCI repositories, instead of authenticated OCI repositories.
Event History
Frequently Asked Questions
Which deployments are exposed to token disclosure?
The issue affects systems that download apps, runtimes, or extensions from OCI repositories requiring authentication, particularly multi-user systems where another local user can read the token file. Downloads from libostree repositories such as Flathub are not affected.
Does a restrictive umask prevent this issue?
No. Unlike the related issue GHSA-r9w3-qx54-qvc8, this behavior is not mitigated by using a restrictive umask.
What can be done if an update cannot be installed immediately?
There is no known direct mitigation other than updating. As alternatives, use libostree repositories such as Flathub or unauthenticated/public OCI repositories instead of authenticated OCI repositories.
What version contains the fix?
The issue was patched in Flatpak 1.18.4, with a change that stops persisting the bearer token to the child repository on disk.