CVE-2023-40299: High severity macos vulnerability
Published Oct 4, 2023
·Updated
Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLDINSERTLIBRARIES environment variable.
Affected Software
4 affected components
All of the following
Apple macOS
konghq Insomnia=2023.4.0
konghq Insomnia=2023.4.0
Apple macOS
Remediation
Patch Available
Event History
Oct 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Kong Insomnia vulnerability?
The vulnerability ID for this Kong Insomnia vulnerability is CVE-2023-40299.
2
What are the affected software versions?
The affected software version is Kong Insomnia 2023.4.0 on macOS.
3
What can attackers do with this vulnerability?
Attackers can execute code, access restricted files, or make requests for TCC permissions using the DYLD_INSERT_LIBRARIES environment variable.
4
How severe is this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.8.
5
How can I fix this vulnerability?
To fix this vulnerability, update to a patched version of Kong Insomnia by following the official release and changelog information provided by the Insomnia team.