Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
History

Tue, 15 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 15:30:00 +0000


Tue, 15 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Description Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
Title Element Desktop vulnerable to potential exposure of access token via authenticated media
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-15T15:02:54.059Z

Updated: 2024-10-15T17:28:19.064Z

Reserved: 2024-09-30T21:28:53.233Z

Link: CVE-2024-47771

cve-icon Vulnrichment

Updated: 2024-10-15T17:28:12.493Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-15T15:15:12.800

Modified: 2024-10-16T16:38:43.170

Link: CVE-2024-47771

cve-icon Redhat

No data.