cbcvebase.
CVE-2019-8308
published 2019-02-12

CVE-2019-8308: Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side…

PriorityP433high8.2CVSS 3.0
AVLACLPRLUIRSCCHIHAH
EPSS
0.47%
37.8th percentile
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianflatpak< flatpak 1.2.3-1 (bookworm)flatpak 1.2.3-1 (bookworm)
flatpakflatpak< 1.0.71.0.7
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak>= 0 < 1.2.3-11.2.3-1
flatpakflatpak1.1.0 – 1.1.3
flatpakflatpak1.2.0 – 1.2.3
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.