PT-2023-19386 · Signal · Signal Desktop+1
CVE-2023-24069
·
Publicado
2023-01-23
·
Atualizado
2025-04-02
CVSS v3.1
3.3
Baixa
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Signal Desktop versions prior to 6.2.0
Description
The issue allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. Local filesystem access is needed by the attacker.
Recommendations
For Signal Desktop versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the attachments.noindex directory to minimize the risk of exploitation. Avoid using the desktop application to store sensitive attachments until the issue is resolved.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Esignal
Signal Desktop