CVE-2024-31784: Medium severity typora vulnerability
Published Apr 16, 2024
·Updated
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.
Affected Software
2 affected components
Typora typora<1.8.10
Typora typora<=1.8.10
Event History
Apr 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31784?
CVE-2024-31784 has a high severity level due to its potential for sensitive information exposure and arbitrary code execution.
2
How do I fix CVE-2024-31784?
To mitigate CVE-2024-31784, update Typora to version 1.8.11 or later.
3
Who is affected by CVE-2024-31784?
Users of Typora versions 1.8.10 and earlier are affected by CVE-2024-31784.
4
What type of attack does CVE-2024-31784 involve?
CVE-2024-31784 involves a local attacker executing arbitrary code through a crafted payload.
5
What software is vulnerable to CVE-2024-31784?
Typora v.1.8.10 and earlier versions are vulnerable to CVE-2024-31784.