Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35222

Опубликовано: 23 мая 2024
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the dangerousRemoteDomainIpcAccess in v1 and in the capabilities in v2. Valid commands with potentially unwanted consequences ("delete project", "transfer credits", etc.) could be invoked by an attacker that controls the content of an iframe running inside a Tauri app. This vulnerability has been patched in versions 1.6.7 and 2.0.0-beta.19.

EPSS

Процентиль: 11%
0.00037
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.9
github
больше 1 года назад

iFrames Bypass Origin Checks for Tauri API Access Control

EPSS

Процентиль: 11%
0.00037
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-284