CVE-2023-43799
The Altair Desktop Client Does Not Sanitize External URLs before passing them to the underlying system
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
04 oct 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system. Moreover, Altair GraphQL Client also does not isolate the context of the renderer process. This affects versions of the software running on MacOS, Windows, and Linux. Version 5.2.5 fixes this issue.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Productos afectados
altair-graphql · altair¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →