SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web contents. Because, prior to version 0.10.35, the deep link URLs were not sanitized properly in all cases, a one-click remote code execution can be achieved in cases when a device is connected, the user is presented with a malicious link and clicks it from within the application. As of version 0.10.35, the custom protocol links within the electron application are now being parsed and sanitized properly.
References
Link | Resource |
---|---|
https://github.com/SideQuestVR/SideQuest/security/advisories/GHSA-3v86-cf9q-x4x7 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-01-04T14:48:34.782Z
Updated: 2024-01-04T14:48:34.782Z
Reserved: 2023-12-29T03:00:44.953Z
Link: CVE-2024-21625
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-04T15:15:11.030
Modified: 2024-01-11T16:52:43.513
Link: CVE-2024-21625
JSON object: View
Redhat Information
No data.
CWE