VDB

CVE-2024-47771

CVE-2024-47771 PUBLISHED CVSS 7 HIGH

Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.

EPSS 0.59% · 46.1th percentile

Risk Scores

CVSS 4.0
7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS Score
0.59%
46.1th percentile

Affected Products

VendorProductVersions
element-hqelement-desktop*, >= 1.11.70, < 1.11.81

Timeline

  • Jan 21, 1970 Security Advisory
  • Oct 15, 2024 CVE Published
  • Oct 15, 2024 PoC Published
  • Oct 15, 2024 PoC Published
  • Oct 16, 2024 EPSS Score
  • Oct 17, 2024 Coalition ESS Score
  • Nov 4, 2024 EPSS Score
  • Nov 23, 2024 EPSS Score
  • Nov 29, 2024 Coalition ESS Score
  • Dec 13, 2024 EPSS Score
  • Jan 1, 2025 EPSS Score
  • Jan 19, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›