Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xdg-desktop-portal | Flatpak | * | 1.20.4 (excluding) |
| Xdg-desktop-portal | Flatpak | 1.21.0 (including) | 1.21.0 (including) |
| Xdg-desktop-portal | Ubuntu | esm-infra-legacy/xenial | * |
| Xdg-desktop-portal | Ubuntu | esm-infra/bionic | * |
| Xdg-desktop-portal | Ubuntu | esm-infra/focal | * |
| Xdg-desktop-portal | Ubuntu | esm-infra/xenial | * |
| Xdg-desktop-portal | Ubuntu | jammy | * |
| Xdg-desktop-portal | Ubuntu | noble | * |
| Xdg-desktop-portal | Ubuntu | questing | * |
| Xdg-desktop-portal | Ubuntu | upstream | * |