Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles
CVE-2023-34460
4.8MEDIUM
What is CVE-2023-34460?
Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. $HOME/*), but a regression was introduced when a configuration option for this behavior was implemented. Only Tauri applications using wildcard scopes in the fs endpoint are affected. The regression has been patched on version 1.4.1.
Affected Version(s)
tauri = 1.4.0
