github.com
https://github.com/element-hq/element-desktop/commit/6c78684e84ba7f460aedba6f017760e2323fdf4b CVE-2024-47771
HIGH
Element Desktop vulnerable to potential exposure of access token via authenticated media
Record summary
CVE-2024-47771 has a selected CVSS score of 7.0 (high).
Description
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
element-desktopBrowse element-hq / element-desktop | CVE List | >= 1.11.70, < 1.11.81 | affected |
References
3github.comConfirmation
https://github.com/element-hq/element-desktop/security/advisories/GHSA-963w-49j9-gxj6 github.com
https://github.com/element-hq/element-web/commit/63c8550791a0221189f495d6458fee7db601c789