CVE-2021-23827: Medium severity keybase vulnerability
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23827?
CVE-2021-23827 is a vulnerability in the Keybase Desktop Client before version 5.6.0 on Windows and macOS, and before version 5.6.1 on Linux.
How does CVE-2021-23827 affect Keybase Desktop Client?
CVE-2021-23827 allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories.
Which operating systems are affected by CVE-2021-23827?
Keybase Desktop Client before version 5.6.0 is affected on Windows and macOS, and before version 5.6.1 on Linux.
How severe is CVE-2021-23827?
CVE-2021-23827 has a severity rating of 5.5, which is considered medium.
Is there a fix available for CVE-2021-23827?
Yes, the fix for CVE-2021-23827 is available in Keybase Desktop Client version 5.6.0 on Windows and macOS, and version 5.6.1 on Linux.