flatpak is vulnerable to Improper Authorization
54
Medium Risk
Flatpak's system helper exposes an unprivileged RemoveLocalRef method that a local user with an active session can call to remove the remote ref of an installed system app or runtime. With the remote ref gone, the anti-downgrade check cannot find the reference date it compares against and silently passes, allowing the app to be downgraded to an older version. On multi-user systems this lets one user expose others to an app version with known vulnerabilities. The fix falls back to the deployed ref commit when checking up and downgrades and prevents removing deployed refs through the system helper.
You are affected if you are using a version that falls within the vulnerable range and the system is multi-user.
flatpak is vulnerable to Improper Authorization in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant