CVE-2024-45833

Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:*

History

23 Sep 2024, 13:43

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:*
First Time Mattermost
Mattermost mattermost Mobile
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : 4.5
v2 : unknown
v3 : 6.5
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory

16 Sep 2024, 15:30

Type Values Removed Values Added
Summary
  • (es) Las versiones &lt;=2.18.0 de Mattermost Mobile Apps no pueden deshabilitar el autocompletado durante el inicio de sesión al escribir la contraseña y se selecciona la contraseña visible, lo que permite que la contraseña se guarde en el diccionario cuando el usuario tiene Swiftkey como teclado predeterminado, el enmascaramiento está desactivado y la contraseña contiene un carácter especial.

16 Sep 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-16 07:15

Updated : 2024-09-23 13:43


NVD link : CVE-2024-45833

Mitre link : CVE-2024-45833

CVE.ORG link : CVE-2024-45833


JSON object : View

Products Affected

mattermost

  • mattermost_mobile
CWE
NVD-CWE-Other CWE-693

Protection Mechanism Failure