Описание
Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the dangerousRemoteDomainIpcAccess in v1 and in the capabilities in v2. Valid commands with potentially unwanted consequences ("delete project", "transfer credits", etc.) could be invoked by an attacker that controls the content of an iframe running inside a Tauri app. This vulnerability has been patched in versions 1.6.7 and 2.0.0-beta.19.
EPSS
Процентиль: 11%
0.00037
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 5.9
github
больше 1 года назад
iFrames Bypass Origin Checks for Tauri API Access Control
EPSS
Процентиль: 11%
0.00037
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-284