Логотип exploitDog
bind:CVE-2021-21261
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21261

Количество 10

Количество 10

ubuntu логотип

CVE-2021-21261

около 5 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-...

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2021-21261

около 5 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-21261

около 5 лет назад

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-san

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2021-21261

около 5 лет назад

Flatpak is a system for building, distributing, and running sandboxed ...

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0520-1

почти 5 лет назад

Security update for flatpak, libostree, xdg-desktop-portal, xdg-desktop-portal-gtk

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1094-1

почти 5 лет назад

Security update for flatpak, libostree, xdg-desktop-portal, xdg-desktop-portal-gtk

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0411

около 5 лет назад

ELSA-2021-0411: flatpak security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-0304

около 5 лет назад

ELSA-2021-0304: flatpak security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2990-1

больше 3 лет назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3284-1

больше 3 лет назад

Security update for flatpak

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-...

CVSS3: 7.3
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-...

CVSS3: 8.8
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-san

CVSS3: 7.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed ...

CVSS3: 7.3
0%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0520-1

Security update for flatpak, libostree, xdg-desktop-portal, xdg-desktop-portal-gtk

0%
Низкий
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1094-1

Security update for flatpak, libostree, xdg-desktop-portal, xdg-desktop-portal-gtk

0%
Низкий
почти 5 лет назад
oracle-oval логотип
ELSA-2021-0411

ELSA-2021-0411: flatpak security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2021-0304

ELSA-2021-0304: flatpak security update (IMPORTANT)

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:2990-1

Security update for flatpak

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3284-1

Security update for flatpak

больше 3 лет назад

Уязвимостей на страницу