CVE-2022-21682 is a path traversal vulnerability affecting Flatpak versions prior to 1.12.3 and 1.10.6, specifically impacting flatpak-builder when using the --mirror-screenshots-url option. This flaw allows for the creation of empty directories in arbitrary locations where the user has write permissions, and a malicious application could potentially replace the appstream-util binary to execute more hostile actions. With a CVSS score of 6.5 (MEDIUM), it has a network attack vector and low attack complexity, with a high impact on integrity but no impact on confidentiality or availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.7CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | ||
>= 1.11.1, < 1.12.4CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | ||
< 1.2.2CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak-builder:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.