VDB
CVE-2024-47771
CVE-2024-47771
PUBLISHED
CVSS 7 HIGH
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
EPSS 0.59% · 46.1th percentile
Risk Scores
CVSS 4.0
7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS Score
0.59%
46.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| element-hq | element-desktop | *, >= 1.11.70, < 1.11.81 |
Timeline
- Jan 21, 1970 Security Advisory
- Oct 15, 2024 CVE Published
- Oct 15, 2024 PoC Published
- Oct 15, 2024 PoC Published
- Oct 16, 2024 EPSS Score
- Oct 17, 2024 Coalition ESS Score
- Nov 4, 2024 EPSS Score
- Nov 23, 2024 EPSS Score
- Nov 29, 2024 Coalition ESS Score
- Dec 13, 2024 EPSS Score
- Jan 1, 2025 EPSS Score
- Jan 19, 2025 EPSS Score