First published: Mon Feb 22 2021(Updated: )
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Keybase Keybase | <5.6.0 | |
Apple macOS | ||
Microsoft Windows | ||
Keybase Keybase | <5.6.1 | |
Redhat Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23827 is a vulnerability in the Keybase Desktop Client before version 5.6.0 on Windows and macOS, and before version 5.6.1 on Linux.
CVE-2021-23827 allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories.
Keybase Desktop Client before version 5.6.0 is affected on Windows and macOS, and before version 5.6.1 on Linux.
CVE-2021-23827 has a severity rating of 5.5, which is considered medium.
Yes, the fix for CVE-2021-23827 is available in Keybase Desktop Client version 5.6.0 on Windows and macOS, and version 5.6.1 on Linux.