PT-2023-19386 · Signal · Signal Desktop+1

CVE-2023-24069

·

Publicado

2023-01-23

·

Atualizado

2025-04-02

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Signal Desktop versions prior to 6.2.0
Description The issue allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. Local filesystem access is needed by the attacker.
Recommendations For Signal Desktop versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the attachments.noindex directory to minimize the risk of exploitation. Avoid using the desktop application to store sensitive attachments until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24069

Produtos afetados

Esignal
Signal Desktop