CVE-2024-45835: Insufficient Electron Fuses Configuration
Published Sep 16, 2024
·Updated
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Affected Software
3 affected componentsFixes available
npm/mattermost-desktop<5.9.0
5.9.0
Mattermost Mattermost Desktop<5.9.0
Mattermost Mattermost Server<5.9.0
Remediation
Information
Update Mattermost Desktop App to versions 5.9.0 or higher.
Event History
Sep 16, 2024
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
RemedyDescriptionSeverityWeakness
Advisory Published
via GitHub·03:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-45835?
CVE-2024-45835 is considered a medium severity vulnerability due to its potential to expose sensitive data.
2
How do I fix CVE-2024-45835?
To fix CVE-2024-45835, upgrade Mattermost Desktop App to version 5.9.0 or higher.
3
Which versions are affected by CVE-2024-45835?
CVE-2024-45835 affects all versions of Mattermost Desktop App prior to 5.9.0.
4
What types of attacks can exploit CVE-2024-45835?
CVE-2024-45835 can be exploited to gather Chromium cookies or abuse other configuration misconfigurations.
5
Is there a known exploit for CVE-2024-45835?
While no specific exploits are publicly documented for CVE-2024-45835, the vulnerability creates opportunities for attackers to access sensitive information.