Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in xdg-dbus-proxy. The filtering logic applied to D-Bus broadcast messages does not correctly enforce the configured path, interface, and member restrictions. As a result, a malicious or compromised Flatpak application can intercept broadcast signals on the D-Bus session bus and the AT-SPI bus that should have been filtered out, potentially exposing information from other applications on the bus to an unauthorized sandboxed application. Upstream advisory: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c Affected versions: 0.1.6, 0.1.7 Fixed version: 0.1.8 Upstream CVSS: 3.2 (Low)