PT-2024-31800 · Google+1 · Chromium+1

Doyensec

·

Published

2024-09-16

·

Updated

2024-11-01

·

CVE-2024-45835

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Desktop App versions <=5.8.0
Description: The Mattermost Desktop App fails to sufficiently configure Electron Fuses, allowing an attacker to gather Chromium cookies or abuse other misconfigurations via remote or local access. This issue can be exploited locally.
Recommendations: For Mattermost Desktop App versions <=5.8.0, upgrade the affected component to a version that properly configures Electron Fuses to prevent exploitation. As a temporary workaround, consider restricting access to sensitive data stored in Chromium cookies until the issue is resolved.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-45835
CVE-2024-45835
GHSA-XGQ9-7GW6-JR5R

Affected Products

Chromium
Mattermost Desktop App