Flatpak is vulnerable to privilege escalation. The vulnerability exists because Flatpak doesn’t properly validate that the permissions displayed to the user for an app at install time which allows an attacker to send maliciously crafted metadata file.
github.com/flatpak/flatpak/commit/54ec1a482dfc668127eaae57f135e6a8e0bc52da
github.com/flatpak/flatpak/commit/65cbfac982cb1c83993a9e19aa424daee8e9f042
github.com/flatpak/flatpak/commit/93357d357119093804df05acc32ff335839c6451
github.com/flatpak/flatpak/commit/ba818f504c926baaf6e362be8159cfacf994310e
github.com/flatpak/flatpak/commit/d9a8f9d8ccc0b7c1135d0ecde006a75d25f66aee
github.com/flatpak/flatpak/releases/tag/1.10.6
github.com/flatpak/flatpak/releases/tag/1.12.3
github.com/flatpak/flatpak/security/advisories/GHSA-qpjc-vq3c-572j
lists.fedoraproject.org/archives/list/[email protected]/message/APFTBYGJJVJPFVHRXUW5PII5XOAFI4KH/
secdb.alpinelinux.org/edge/community.yaml
secdb.alpinelinux.org/v3.15/community.yaml
www.debian.org/security/2022/dsa-5049