CVE-2024-32462 is a critical sandbox escape vulnerability affecting Flatpak versions prior to 1.10.9, 1.12.9, 1.14.6, and 1.15.8, including those in Fedora Project distributions. A malicious Flatpak application can leverage improper handling of the --command argument to pass arbitrary bubblewrap (bwrap) arguments, such as --bind, allowing for arbitrary code execution outside the sandbox. With a CVSS score of 8.4 (High), this vulnerability poses a significant risk of high confidentiality and integrity impact, as an attacker can escape the sandbox with low privileges and complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.9CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | ||
>= 1.12.0, < 1.12.9CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | ||
>= 1.14.0, < 1.14.6CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | ||
>= 1.15.0, < 1.15.8CPE matchmatch criteria | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.