cvedb.io
CVE-2019-8308
HIGH · CVSS 8.2
EPSS exploitation probability: 0%
Published 2019-02-12T23:29:00.317 · Last modified 2026-06-17T02:41:49.460

Summary

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

Affected products

flatpak — flatpak

Does this affect you?

Add your gear to cvedb and we'll alert you only when flatpak ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.