5.5

CVE-2021-23827

Exploit
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KeybaseKeybase Version < 5.6.0
   ApplemacOS Version-
   MicrosoftWindows Version-
KeybaseKeybase Version < 5.6.1
   RedhatLinux Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.21
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

https://github.com/keybase/client/releases
Third Party Advisory
Release Notes
https://hackerone.com/reports/1074930
Third Party Advisory
Exploit
Issue Tracking
https://johnjhacking.com/blog/cve-2021-23827/
Third Party Advisory
Exploit