
Cloud Vulnerability DB
A community-led vulnerabilities database
The Keybase Clients for macOS and Windows before version 5.9.0 contains a vulnerability (CVE-2022-22779) related to improper removal of exploded messages. The vulnerability was disclosed on February 9, 2022, and affects Keybase applications on macOS and Windows operating systems (NVD).
The vulnerability occurs when the receiving user switches to a non-chat feature and places the host in a sleep state before the sending user explodes the messages. This results in a failure to properly remove exploded messages. The vulnerability has been assigned a CVSS v3.1 base score of 3.7 (Low) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N, and a CVSS v2.0 base score of 4.3 (Medium) (NVD).
The vulnerability could lead to disclosure of sensitive information which was meant to be deleted from a user's filesystem. This occurs when exploded messages fail to be properly removed from the system (NVD).
The vulnerability has been fixed in Keybase version 5.9.0. Users are recommended to upgrade to this version or later to address the security issue (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."