summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorFlorian Klink <flokli@flokli.de>2024-10-13 16:28:39 +0300
committerFlorian Klink <flokli@flokli.de>2024-10-13 16:39:35 +0300
commit32309e44684573695f70b7e3845925be05f8db9f (patch)
treec3fc49ffd2c41a2a65c1740bdd7cab2adf64fab9
parentneovim.tests: add a test for passthru.initRc (diff)
downloadnixpkgs-32309e44684573695f70b7e3845925be05f8db9f.tar.gz
wire-desktop: add CVE-2024-6775 to knownVulnerabilities
wire-desktop on Linux uses electron 29.4.5, which is known to be vulnerable to CVE-2024-6775: https://github.com/wireapp/wire-desktop/blob/cf65edb5981be370f3284555512696175099e234/package.json#L85 The MacOS version is even older, and affected by this too.
-rw-r--r--pkgs/applications/networking/instant-messengers/wire-desktop/default.nix1
1 files changed, 1 insertions, 0 deletions
diff --git a/pkgs/applications/networking/instant-messengers/wire-desktop/default.nix b/pkgs/applications/networking/instant-messengers/wire-desktop/default.nix
index 2030a3f467b4..1b4ae2a4e74a 100644
--- a/pkgs/applications/networking/instant-messengers/wire-desktop/default.nix
+++ b/pkgs/applications/networking/instant-messengers/wire-desktop/default.nix
@@ -57,6 +57,7 @@ let
homepage = "https://wire.com/";
downloadPage = "https://wire.com/download/";
sourceProvenance = with sourceTypes; [ binaryNativeCode ];
+ knownVulnerabilities = [ "CVE-2024-6775" ];
license = licenses.gpl3Plus;
maintainers = with maintainers; [
arianvp