CVE-2023-46115
- EPSS 0.06%
- Veröffentlicht 20.10.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 08:27:54
Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base itself but a commonly used misconfiguration which could lead to leaking of the private key and updater ...
CVE-2023-34460
- EPSS 0.07%
- Veröffentlicht 23.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:18
Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. `...
CVE-2023-31134
- EPSS 0.23%
- Veröffentlicht 09.05.2023 14:15:13
- Zuletzt bearbeitet 21.11.2024 08:01:27
Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated from external websites, but in versions 1.0.0 until 1.0.9, 1.1.0 until 1.1.4, and 1.2.0 until 1.2.5, the isolation can be bypassed b...
CVE-2022-46171
- EPSS 0.51%
- Veröffentlicht 23.12.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:30:15
Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed ...
CVE-2022-41874
- EPSS 0.18%
- Veröffentlicht 10.11.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:23:57
Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dial...
CVE-2022-39215
- EPSS 0.43%
- Veröffentlicht 15.09.2022 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:48
Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it was possible to display directory listings outside of the defined `fs` scope. This required a crafted...