CVE-2023-43091

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:gnome-maps:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gnome-maps:*:*:*:*:*:*:*:*

History

06 Aug 2025, 12:46

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2239091 - () https://bugzilla.redhat.com/show_bug.cgi?id=2239091 - Issue Tracking, Third Party Advisory
References () https://gitlab.gnome.org/GNOME/gnome-maps/-/commit/d26cd774d524404ef7784e6808f551de83de4bea - () https://gitlab.gnome.org/GNOME/gnome-maps/-/commit/d26cd774d524404ef7784e6808f551de83de4bea - Patch
References () https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588 - () https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588 - Exploit, Issue Tracking
CWE CWE-94
First Time Gnome
Gnome gnome-maps
CPE cpe:2.3:a:gnome:gnome-maps:*:*:*:*:*:*:*:*

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en GNOME Maps, que es vulnerable a un ataque de inyección de código a través de su archivo de configuración service.json. Si el archivo de configuración es malicioso, puede ejecutar código arbitrario.

17 Nov 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-17 13:15

Updated : 2025-08-06 12:46


NVD link : CVE-2023-43091

Mitre link : CVE-2023-43091

CVE.ORG link : CVE-2023-43091


JSON object : View

Products Affected

gnome

  • gnome-maps
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')