Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2893 Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Github GHSA Github GHSA GHSA-xgq9-7gw6-jr5r Mattermost Desktop App fails to sufficiently configure Electron Fuses
Fixes

Solution

Update Mattermost Desktop App to versions 5.9.0 or higher.


Workaround

No workaround given by the vendor.

References
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00082}

epss

{'score': 0.00097}


Fri, 01 Nov 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Desktop
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server
Mattermost mattermost Desktop

Tue, 17 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Mon, 16 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Title Insufficient Electron Fuses Configuration
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-16T14:42:39.152Z

Reserved: 2024-09-11T15:59:49.550Z

Link: CVE-2024-45835

cve-icon Vulnrichment

Updated: 2024-09-16T14:42:35.975Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-16T15:15:16.803

Modified: 2024-11-01T14:20:56.350

Link: CVE-2024-45835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.