CVE-2023-5339 MEDIUM

CVE-2023-5339: Mattermost Desktop logs all keystrokes during initial run after fresh installation 

Vendor Mattermost
Product Mattermost
Weakness CWE-200 · Info exposure
Published October 17, 2023
Last update September 5, 2024

CVSS base score

4.7/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

Key dates

02Disclosure timeline

October 17, 2023 CVE published
September 5, 2024 Record updated