CVE-2023-5339: Mattermost Desktop logs all keystrokes during initial run after fresh installation
Published Oct 17, 2023
·Updated
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
Affected Software
1 affected component
Mattermost Mattermost Desktop<=5.4.0
Remediation
Information
Update Mattermost Desktop to versions 5.5.0 or higher.
Event History
Oct 17, 2023
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5339.
2
What is the title of the vulnerability?
The title of the vulnerability is Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation.
3
What is the impact of this vulnerability?
The impact of this vulnerability is that all keystrokes, including password entry, are logged.
4
Which version of Mattermost Desktop is affected?
Mattermost Desktop version up to and including 5.4.0 is affected.
5
How severe is this vulnerability?
This vulnerability has a severity rating of 5.5 (medium).