CVE-2021-23827
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories.
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- keybase/keybase
- Source
- cve@mitre.org
References
- https://github.com/keybase/client/releasesRelease Notes, Third Party Advisory
- https://hackerone.com/reports/1074930Exploit, Issue Tracking, Third Party Advisory
- https://johnjhacking.com/blog/cve-2021-23827/Exploit, Third Party Advisory
- https://github.com/keybase/client/releasesRelease Notes, Third Party Advisory
- https://hackerone.com/reports/1074930Exploit, Issue Tracking, Third Party Advisory
- https://johnjhacking.com/blog/cve-2021-23827/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.