CVE-2022-21817

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/02/2022
Last modified:
24/07/2023

Description

NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:omniverse_launcher:*:*:*:*:*:*:*:* 1.5.2 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools