Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2893 Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Github GHSA Github GHSA GHSA-xgq9-7gw6-jr5r Mattermost Desktop App fails to sufficiently configure Electron Fuses
Fixes

Solution

Update Mattermost Desktop App to versions 5.9.0 or higher.


Workaround

No workaround given by the vendor.

References
History

Sun, 13 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00082}

epss

{'score': 0.00097}


Fri, 01 Nov 2024 23:45:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost mattermost Desktop
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server
Mattermost mattermost Desktop

Tue, 17 Sep 2024 21:30:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Tue, 17 Sep 2024 00:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 23:45:00 +0900

Type Values Removed Values Added
Description Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Title Insufficient Electron Fuses Configuration
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-16T14:42:39.152Z

Reserved: 2024-09-11T15:59:49.550Z

Link: CVE-2024-45835

cve-icon Vulnrichment

Updated: 2024-09-16T14:42:35.975Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-16T15:15:16.803

Modified: 2024-11-01T14:20:56.350

Link: CVE-2024-45835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses