PT-2025-22525 · Unknown · Wire-Webapp
Sanojwr
·
Publicado
2025-05-22
·
Atualizado
2025-05-30
·
CVE-2025-48066
CVSS v3.1
6.0
Média
| Vetor | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wire-webapp versions prior to 2025-05-14-production.0
Description
A regression issue in the function to delete local data causes the client's local database not to be deleted upon user logout, even when instructed to do so. This affects both temporary clients and regular clients attempting to delete personal information and conversations. Access to the machine is required to access the data, and if encryption-at-rest is used, cryptographic material cannot be exported.
Recommendations
For versions prior to 2025-05-14-production.0, manually delete the database on devices where the option "This is a public computer" was used prior to login or a logout with the request to delete local data has happened before.
Update to wire-webapp version 2025-05-14-production.0 to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wire-Webapp