Home
MEDIUM: 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NDefault status
unaffected
Any version
affected
5.5.0
unaffected
Description
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version
5.5.0
Credits
Patrice Kolb
References
mattermost.com/security-updates
mattermost.com/security-updates