First published: Tue Nov 12 2024(Updated: )
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor | <1.11.85 | |
Element Desktop | <1.11.85 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51749 has been classified with a moderate severity due to the risk of unauthorized file downloads.
To remediate CVE-2024-51749, upgrade to Element Web and Desktop version 1.11.85 or later.
CVE-2024-51749 affects Element Web and Element Desktop versions prior to 1.11.85.
Yes, CVE-2024-51749 can potentially be exploited to trigger unwanted file downloads via manipulated thumbnails.
Yes, a patch is included in Element versions 1.11.85 and newer, addressing the vulnerability.