CVE-2021-23827
Summary
| CVE | CVE-2021-23827 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 00:15:00 UTC |
| Updated | 2021-09-08 17:23:00 UTC |
| Description | Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | - | All | All | All |
| Operating System | Apple | Mac Os | - | All | All | All |
| Operating System | Apple | Mac Os | - | All | All | All |
| Operating System | Apple | Mac Os | - | All | All | All |
| Application | Keybase | Keybase | All | All | All | All |
| Operating System | Keybase | Keybase | All | All | All | All |
| Application | Keybase | Keybase | All | All | All | All |
| Operating System | Keybase | Keybase | All | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Redhat | Linux | - | All | All | All |
| Operating System | Redhat | Linux | - | All | All | All |
| Operating System | Redhat | Linux | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Releases · keybase/client · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| HackerOne | MISC | hackerone.com | Exploit, Issue Tracking, Third Party Advisory |
| John J Hacking | MISC | johnjhacking.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.