Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-52968

Опубликовано: 23 июн. 2025
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange for an empty cookie store, although this would add substantial complexity, and would not be considered a desirable or expected behavior by all users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.

A potential Cross-site request forgery (CSRF) flaw was found in xdg-utils. The xdg-open function in xdg-utils through version 1.2.1 can send requests containing SameSite=Strict cookies, facilitating a Cross-site request forgery (CSRF) attack vector.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10flatpak-xdg-utilsFix deferred
Red Hat Enterprise Linux 10xdg-utilsFix deferred
Red Hat Enterprise Linux 6xdg-utilsOut of support scope
Red Hat Enterprise Linux 7xdg-utilsFix deferred
Red Hat Enterprise Linux 8flatpak-xdg-utilsFix deferred
Red Hat Enterprise Linux 8xdg-utilsFix deferred
Red Hat Enterprise Linux 9flatpak-xdg-utilsFix deferred
Red Hat Enterprise Linux 9xdg-utilsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-420
https://bugzilla.redhat.com/show_bug.cgi?id=2374342xdg-utils: xdg-open bypassing SameSite=Strict

EPSS

Процентиль: 2%
0.00014
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
ubuntu
около 2 месяцев назад

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange for an empty cookie store, although this would add substantial complexity, and would not be considered a desirable or expected behavior by all users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.

CVSS3: 2.7
nvd
около 2 месяцев назад

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange for an empty cookie store, although this would add substantial complexity, and would not be considered a desirable or expected behavior by all users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.

CVSS3: 2.7
debian
около 2 месяцев назад

xdg-open in xdg-utils through 1.2.1 can send requests containing SameS ...

CVSS3: 2.7
github
около 2 месяцев назад

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.

EPSS

Процентиль: 2%
0.00014
Низкий

2.7 Low

CVSS3