No CVSS.
lement Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
No configuration.
16 Oct 2024, 16:38
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
15 Oct 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
15 Oct 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-10-15 15:15
Updated : 2024-10-16 16:38
NVD link : CVE-2024-47771
Mitre link : CVE-2024-47771
CVE.ORG link : CVE-2024-47771
JSON object : View
No product.
Exposure of Sensitive Information to an Unauthorized Actor