{"id":"CVE-2023-43091","summary":"Gnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss)  via its service.json","details":"A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.","modified":"2026-08-12T03:51:42.198021650Z","published":"2024-11-17T12:25:49.293Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43091.json","cna_assigner":"fedora","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43091.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43091"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2239091"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/gnome-maps/-/commit/d26cd774d524404ef7784e6808f551de83de4bea"},{"type":"PACKAGE","url":"https://gitlab.gnome.org/GNOME/gnome-maps"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/gnome-maps","events":[{"introduced":"789b6f9b3410d2c980d2274b497844a9e3acabcd"},{"fixed":"9e4b9289259b33e7329601a14bf00c86ac22f8f6"},{"introduced":"c64977b2c7881fd797b3593f019cf1531c651e14"},{"fixed":"cac93ce984c1a49beebe5000910742e3b758f614"},{"fixed":"d26cd774d524404ef7784e6808f551de83de4bea"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:gnome-maps:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"43.0"},{"fixed":"43.7"},{"introduced":"44.0"},{"fixed":"44.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v45.beta","v44.3","v45.alpha","v44.2","v44.1","v43.5","v44.0","v43.4","v43.3","v43.2","v43.1","v43.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43091.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}