Executive brief
Mattermost Desktop is a messaging and collaboration application used by teams to communicate and coordinate work. Versions up to 5.8.0 fail to properly configure Electron Fuses, a security hardening mechanism, allowing an attacker with local or remote access to extract stored Chromium browser cookies or exploit other misconfigurations. This could lead to account hijacking or data theft.
Technical details
The Mattermost Desktop App (npm package mattermost-desktop through version 5.8.0) fails to sufficiently configure Electron Fuses, a framework that hardens Electron applications by disabling or restricting powerful APIs. The vulnerability is classified as CWE-693 (Protection Mechanism Failure). An attacker with local access or remote access capability can bypass the intended security controls to gather Chromium cookies or abuse other misconfigurations. The fix is available in version 5.9.0 or later, which properly configures Electron Fuses to restrict unauthorized access.
Affected products
- Mattermost Desktop <=5.8.0
Timeline
- 2024-09-16: disclosed
- 2024-09-16: patched: Fix available in version 5.9.0