CVE-2023-40299
Published Oct 4, 2023
·Updated
Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.
Affected Software
4 affected components
All of the following
Apple macOS
konghq Insomnia=2023.4.0
konghq Insomnia=2023.4.0
Apple macOS
Remediation
Patch Available
Event History
Oct 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Kong Insomnia vulnerability?
The vulnerability ID for this Kong Insomnia vulnerability is CVE-2023-40299.
2
What are the affected software versions?
The affected software version is Kong Insomnia 2023.4.0 on macOS.
3
What can attackers do with this vulnerability?
Attackers can execute code, access restricted files, or make requests for TCC permissions using the DYLD_INSERT_LIBRARIES environment variable.
4
How severe is this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.8.
5
How can I fix this vulnerability?
To fix this vulnerability, update to a patched version of Kong Insomnia by following the official release and changelog information provided by the Insomnia team.