Bugzilla – Bug 1215599
VUL-0: CVE-2023-43091: gnome-maps: code injection attack via its service.json
Last modified: 2023-09-22 07:30:59 UTC
CVE-2023-43091 GNOME Maps is vulnerable to a code injection attack (similar to XSS) via its service.json configuration file downloaded from https://static.gnome.org/gis.gnome.org/v1/service.json. If the configuration file is malicious, it may execute arbitrary code. Affected versions: 43 prior to 43.7, 44 prior to 44.4 Discoverer/Credit: Michael Evans References, additional information: https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588 https://gitlab.gnome.org/GNOME/gnome-maps/-/commit/d26cd774d524404ef7784e6808f551de83de4bea References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-43091 https://bugzilla.redhat.com/show_bug.cgi?id=2239091
openSUSE:Factory already fixed, openSUSE:Backports:SLE-15-SP* on older, unaffected version.