CVE-2019-8308

Severity
8.2HIGH
EPSS
0.1%
top 80.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 13

Description

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages5 packages

Also affects: Debian Linux 10.0, 9.0, Enterprise Linux 7.6

🔴Vulnerability Details

3
GHSA
GHSA-26wh-22xw-qfqx: Flatpak before 12022-05-13
OSV
CVE-2019-8308: Flatpak before 12019-02-12
CVEList
CVE-2019-8308: Flatpak before 12019-02-12

📋Vendor Advisories

2
Red Hat
flatpak: potential /proc based sandbox escape2019-02-11
Debian
CVE-2019-8308: flatpak - Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the app...2019

💬Community

2
Bugzilla
CVE-2019-8308 flatpak: potential /proc based sandbox escape [fedora-all]2019-02-11
Bugzilla
CVE-2019-8308 flatpak: potential /proc based sandbox escape2019-02-11
CVE-2019-8308 (HIGH CVSS 8.2) | Flatpak before 1.0.7 | cvebase.io