7.8

CVE-2023-40299

Exploit
Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KonghqInsomnia Version2023.4.0
   ApplemacOS Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.268
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-114 Process Control

Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.

https://github.com/Kong/insomnia/pull/6217/commits
Patch
https://github.com/Kong/insomnia/releases
Release Notes
https://insomnia.rest/changelog
Release Notes
https://www.angelystor.com/posts/cve-2023-40299/
Third Party Advisory
Exploit