CVE-2023-5920

LOW

Mattermost Desktop < 5.5.1 - Unauthorized Keyboard Input Exposure via macOS Secure Input Bypass

Title source: llm
STIX 2.1

Description

Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.

References (1)

Core 1
Core References

Scores

CVSS v3 2.9
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
mattermost/mattermost_desktop < 5.5.1
Published Nov 02, 2023
Tracked Since Feb 18, 2026