{"id":"UBUNTU-CVE-2023-28101","details":"Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the `flatpak(1)` command-line interface by setting other permissions to crafted values that contain non-printable control characters such as `ESC`. A fix is available in versions 1.10.8, 1.12.8, 1.14.4, and 1.15.4. As a workaround, use a GUI like GNOME Software rather than the command-line interface, or only install apps whose maintainers you trust.","modified":"2026-09-10T16:30:18.848287104Z","published":"2023-03-16T16:15:00Z","upstream":["CVE-2023-28101"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-28101"},{"type":"REPORT","url":"https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869"},{"type":"REPORT","url":"https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c"},{"type":"REPORT","url":"https://github.com/flatpak/flatpak/commit/409e34187de2b2b2c4ef34c79f417be698830f6c"},{"type":"REPORT","url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-h43h-fwqx-mpp8"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-28101"}],"affected":[{"package":{"name":"flatpak","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/flatpak?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.7-5","0.10.0-1","0.10.0-2","0.10.1-1","0.10.2-1","0.10.2.1-1","0.10.2.1-2","0.10.3-1","0.11.1-0ubuntu1","0.11.3-2","0.11.3-3","0.11.7-0ubuntu0.1","1.0.1-0ubuntu0.1","1.0.6-0ubuntu0.1","1.0.7-0ubuntu0.18.04.1","1.0.8-0ubuntu0.18.04.1","1.0.9-0ubuntu0.1","1.0.9-0ubuntu0.2","1.0.9-0ubuntu0.3","1.0.9-0ubuntu0.4","1.0.9-0ubuntu0.4+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0.9-0ubuntu0.4+esm1","binary_name":"flatpak"},{"binary_name":"flatpak-tests","binary_version":"1.0.9-0ubuntu0.4+esm1"},{"binary_version":"1.0.9-0ubuntu0.4+esm1","binary_name":"gir1.2-flatpak-1.0"},{"binary_version":"1.0.9-0ubuntu0.4+esm1","binary_name":"libflatpak0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28101.json"}},{"package":{"name":"flatpak","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/flatpak?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.3-1","1.6.0-1","1.6.1-1","1.6.2-1","1.6.3-1","1.6.5-0ubuntu0.1","1.6.5-0ubuntu0.2","1.6.5-0ubuntu0.3","1.6.5-0ubuntu0.4","1.6.5-0ubuntu0.5","1.6.5-0ubuntu0.5+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"flatpak","binary_version":"1.6.5-0ubuntu0.5+esm1"},{"binary_name":"flatpak-tests","binary_version":"1.6.5-0ubuntu0.5+esm1"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.6.5-0ubuntu0.5+esm1"},{"binary_version":"1.6.5-0ubuntu0.5+esm1","binary_name":"libflatpak0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28101.json"}},{"package":{"name":"flatpak","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/flatpak?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.2-3","1.12.2-1","1.12.2-2","1.12.3-1","1.12.4-1","1.12.5-1","1.12.6-1","1.12.7-1","1.12.7-1ubuntu0.1","1.12.7-1ubuntu0.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.12.7-1ubuntu0.1+esm1","binary_name":"flatpak"},{"binary_name":"flatpak-tests","binary_version":"1.12.7-1ubuntu0.1+esm1"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.12.7-1ubuntu0.1+esm1"},{"binary_version":"1.12.7-1ubuntu0.1+esm1","binary_name":"libflatpak0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28101.json"}},{"package":{"name":"flatpak","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/flatpak?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.14.4-2","1.14.5-1","1.14.5-1build1","1.14.5-1build4","1.14.5-1build5","1.14.5-1build6","1.14.6-1","1.14.6-1ubuntu0.1","1.14.6-1ubuntu0.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"flatpak","binary_version":"1.14.6-1ubuntu0.1+esm1"},{"binary_name":"flatpak-tests","binary_version":"1.14.6-1ubuntu0.1+esm1"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.14.6-1ubuntu0.1+esm1"},{"binary_name":"libflatpak0","binary_version":"1.14.6-1ubuntu0.1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28101.json"}},{"package":{"name":"flatpak","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/flatpak?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.0-2","1.16.1-1build1","1.16.1-2","1.16.1-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"flatpak","binary_version":"1.16.1-2ubuntu1"},{"binary_name":"flatpak-tests","binary_version":"1.16.1-2ubuntu1"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.16.1-2ubuntu1"},{"binary_name":"libflatpak0","binary_version":"1.16.1-2ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28101.json"}},{"package":{"name":"flatpak","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/flatpak?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.1-2ubuntu1","1.16.1-3ubuntu1","1.16.2-1","1.16.3-1","1.16.3-1build1","1.16.4-1","1.16.4-2","1.16.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"flatpak","binary_version":"1.16.6-1"},{"binary_name":"flatpak-tests","binary_version":"1.16.6-1"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.16.6-1"},{"binary_version":"1.16.6-1","binary_name":"libflatpak0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28101.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}