https://seclists.org/oss-sec/2024/q3/197: flatpak CVE-2024-42472: Access to files outside sandbox for apps using persistent= (--persist)
Published Aug 14, 2024
·Updated
Affected Software
1 affected component
Flatpak Flatpak<1.14.10, >1.15.x<=1.15.10
Frequently Asked Questions
1
What is the severity of CVE-2024-42472?
CVE-2024-42472 is considered a high-severity vulnerability due to the potential for unauthorized access to host files.
2
How do I fix CVE-2024-42472?
To mitigate CVE-2024-42472, users should update to the latest version of Flatpak that addresses this vulnerability.
3
What type of applications are affected by CVE-2024-42472?
Applications using the persistent option (--persist) in Flatpak are affected by CVE-2024-42472.
4
What is the impact of CVE-2024-42472 on user privacy?
CVE-2024-42472 can compromise user privacy by allowing applications to access sensitive files outside their intended sandbox environment.
5
Is there a workaround for CVE-2024-42472 while waiting for a fix?
Until a fix is applied, users can disable the use of persistent directories for applications to avoid exposure to CVE-2024-42472.