Description
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Desktop App to versions 5.8.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2213 | Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS. |
Github GHSA |
GHSA-xgqm-wp7w-mgg2 | Mattermost Desktop App allows for bypassing TCC restrictions on macOS |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 07 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Mattermost Mattermost mattermost Desktop |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple macos Mattermost Mattermost mattermost Desktop |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T03:37:03.683Z
Reserved: 2024-06-14T08:22:33.357Z
Link: CVE-2024-36287
Updated: 2024-08-02T03:37:03.683Z
Status : Modified
Published: 2024-06-14T09:15:09.450
Modified: 2024-11-21T09:21:59.527
Link: CVE-2024-36287
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA