PT-2024-31800 · Mattermost+1 · Mattermost Desktop App+1

·

CVE-2024-45835

·

Published

2024-09-16

·

Updated

2024-11-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Desktop App versions <=5.8.0
Description: The Mattermost Desktop App fails to sufficiently configure Electron Fuses, allowing an attacker to gather Chromium cookies or abuse other misconfigurations via remote or local access. This issue can be exploited locally.
Recommendations: For Mattermost Desktop App versions <=5.8.0, upgrade the affected component to a version that properly configures Electron Fuses to prevent exploitation. As a temporary workaround, consider restricting access to sensitive data stored in Chromium cookies until the issue is resolved.

Exploit

Fix

DoS

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-45835
CVE-2024-45835
GHSA-XGQ9-7GW6-JR5R

Affected Products

Chromium
Mattermost Desktop App