In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.2"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28371.json"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"53595911243962978289097606874560180509",
"293395051054113567024356363208871279662",
"277366325286761857587680373391222403243",
"326000818959828191746522077654869192597",
"321196918525093113140481920217655512467",
"49804637547268882389531205692097127618",
"8251690121638052968625757094808258975",
"227885338067719686680642889369989673852",
"260028020935460372288900778611912583645",
"285304267391085082180688825084999977765"
]
},
"id": "CVE-2023-28371-0b8fadf2",
"signature_version": "v1",
"source": "https://github.com/stellarium/stellarium/commit/1261f74dc4aa6bbd01ab514343424097f8cf46b7",
"signature_type": "Line",
"target": {
"file": "src/scripting/StelScriptOutput.cpp"
},
"deprecated": false
},
{
"digest": {
"length": 902.0,
"function_hash": "131332367628456435425101018616263713921"
},
"id": "CVE-2023-28371-15ce15ca",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/stellarium/stellarium/commit/787a894897b7872ae96e6f5804a182210edd5c78",
"target": {
"function": "StelScriptMgr::prepareScript",
"file": "src/scripting/StelScriptMgr.cpp"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"303728221691636449943264520387451255611",
"230593902007787674813693250773976150493",
"47734859198094678558152211540333167652",
"80109637601504723391936480294380986871",
"163872197253603741743954915001860651362",
"297296004080001500511029935947468487813",
"155052478432239960793641630636852702531",
"213676796580655752738783123126089560460",
"89595302175403460667463594222316883698",
"243901609356039433882450771152910768172",
"178319565779063195393059642092299999817"
]
},
"target": {
"file": "src/scripting/StelScriptMgr.cpp"
},
"deprecated": false,
"id": "CVE-2023-28371-3f2eaa78",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/stellarium/stellarium/commit/787a894897b7872ae96e6f5804a182210edd5c78"
},
{
"source": "https://github.com/stellarium/stellarium/commit/1261f74dc4aa6bbd01ab514343424097f8cf46b7",
"id": "CVE-2023-28371-b0525867",
"signature_version": "v1",
"target": {
"function": "StelScriptOutput::saveOutputAs",
"file": "src/scripting/StelScriptOutput.cpp"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1199.0,
"function_hash": "146475479337413929294242098548304653544"
}
},
{
"digest": {
"length": 163.0,
"function_hash": "311995360783414358128085318359061088311"
},
"id": "CVE-2023-28371-f18649be",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/stellarium/stellarium/commit/787a894897b7872ae96e6f5804a182210edd5c78",
"target": {
"function": "StelScriptMgr::runScript",
"file": "src/scripting/StelScriptMgr.cpp"
}
}
]
"2026-04-12T19:59:20Z"