CVE-2024-45833
MEDIUMMattermost Mobile Apps <=2.18.0 - Info Disclosure
Title source: llmDescription
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
References (1)
Scores
CVSS v3
4.5
EPSS
0.0023
EPSS Percentile
45.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-693
Status
published
Affected Products (1)
mattermost/mattermost_mobile
< 2.19.0
Timeline
Published
Sep 16, 2024
Tracked Since
Feb 18, 2026