GNOME Maps is vulnerable to a code injection attack (similar to XSS) via its service.json configuration file downloaded from https://static.gnome.org/gis.gnome.org/v1/service.json. If the configuration file is malicious, it may execute arbitrary code. Affected versions: 43 prior to 43.7, 44 prior to 44.4 Discoverer/Credit: Michael Evans References, additional information: https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588 https://gitlab.gnome.org/GNOME/gnome-maps/-/commit/d26cd774d524404ef7784e6808f551de83de4bea
Created gnome-maps tracking bugs for this issue: Affects: fedora-all [bug 2239092]