6.1 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .FCStd archive without disabling default external entity resolution or external DTD loading. When Document::restore() opens the document, external entities can read local files through the file URI scheme or initiate server-side requests through the http URI scheme, and resolved content can flow through the characters() callback. This issue is fixed in version 1.1.2.
References
-
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49 x_refsource_CONFIRM
-
https://github.com/FreeCAD/FreeCAD/pull/31271 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/pull/31280 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.2 x_refsource_MISC
Affected products
- ==< 1.1.2
Matching in nixpkgs
pkgs.freecad
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-qt6
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-wayland
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
Package maintainers
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@srounce Samuel Rounce <me@samuelrounce.co.uk>
7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document transient path without rejecting directory components, absolute paths, or parent traversal. A crafted .FCStd archive with a matching FileIncluded XML attribute and ZIP entry can therefore write attacker-controlled content to arbitrary locations accessible to the FreeCAD user, potentially enabling persistence, credential compromise, configuration replacement, or code execution. This issue is fixed in version 1.1.2.
References
-
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-5vqh-3v38-jw2r x_refsource_CONFIRM
-
https://github.com/FreeCAD/FreeCAD/pull/31269 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/pull/31281 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.2 x_refsource_MISC
Affected products
- ==< 1.1.2
Matching in nixpkgs
pkgs.freecad
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-qt6
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-wayland
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
Package maintainers
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@srounce Samuel Rounce <me@samuelrounce.co.uk>
8.5 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
FreeCAD: FEM formula incomplete escape
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the xDisplacementFormula, yDisplacementFormula, and zDisplacementFormula fields of a Fem::ConstraintDisplacement object through TaskDlgFemConstraintDisplacement::accept() into Gui::Command::doCommand. The escaping helper neutralizes quotation marks but not backslashes, allowing crafted formula text to terminate the generated Python string and execute arbitrary Python code with the FreeCAD process's privileges when a victim accepts the dialog. This issue is fixed in version 1.1.2.
References
-
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-2rq3-gx3h-489q x_refsource_CONFIRMexploit
-
https://github.com/FreeCAD/FreeCAD/pull/31267 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/pull/31312 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.2 x_refsource_MISC
Affected products
- ==< 1.1.2
Matching in nixpkgs
pkgs.freecad
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-qt6
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-wayland
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
Package maintainers
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@srounce Samuel Rounce <me@samuelrounce.co.uk>