Vulnerability Details CVE-2021-23827
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.4%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2021-23827
-
cpe:2.3:a:keybase:keybase:0.1.1
-
cpe:2.3:a:keybase:keybase:0.1.2
-
cpe:2.3:a:keybase:keybase:0.1.3
-
cpe:2.3:a:keybase:keybase:0.1.4
-
cpe:2.3:a:keybase:keybase:0.1.5
-
cpe:2.3:a:keybase:keybase:0.1.6
-
cpe:2.3:a:keybase:keybase:0.1.7
-
cpe:2.3:a:keybase:keybase:0.1.8
-
cpe:2.3:a:keybase:keybase:0.8.1
-
cpe:2.3:a:keybase:keybase:1.0.0
-
cpe:2.3:a:keybase:keybase:1.0.0-14
-
cpe:2.3:a:keybase:keybase:1.0.0-15
-
cpe:2.3:a:keybase:keybase:1.0.0-16
-
cpe:2.3:a:keybase:keybase:1.0.0-17
-
cpe:2.3:a:keybase:keybase:1.0.0-18
-
cpe:2.3:a:keybase:keybase:1.0.0-19
-
cpe:2.3:a:keybase:keybase:1.0.0-20
-
cpe:2.3:a:keybase:keybase:1.0.0-21
-
cpe:2.3:a:keybase:keybase:1.0.0-22
-
cpe:2.3:a:keybase:keybase:1.0.0-23
-
cpe:2.3:a:keybase:keybase:1.0.0-24
-
cpe:2.3:a:keybase:keybase:1.0.0-25
-
cpe:2.3:a:keybase:keybase:1.0.0-26
-
cpe:2.3:a:keybase:keybase:1.0.0-27
-
cpe:2.3:a:keybase:keybase:1.0.0-28
-
cpe:2.3:a:keybase:keybase:1.0.0-29
-
cpe:2.3:a:keybase:keybase:1.0.0-29a
-
cpe:2.3:a:keybase:keybase:1.0.0-29b
-
cpe:2.3:a:keybase:keybase:1.0.0-29c
-
cpe:2.3:a:keybase:keybase:1.0.0-29d
-
cpe:2.3:a:keybase:keybase:1.0.0-29e
-
cpe:2.3:a:keybase:keybase:1.0.0-29f
-
cpe:2.3:a:keybase:keybase:1.0.0-29g
-
cpe:2.3:a:keybase:keybase:1.0.0-30
-
cpe:2.3:a:keybase:keybase:1.0.0-31
-
cpe:2.3:a:keybase:keybase:1.0.0-32
-
cpe:2.3:a:keybase:keybase:1.0.0-33
-
cpe:2.3:a:keybase:keybase:1.0.0-34
-
cpe:2.3:a:keybase:keybase:1.0.0-35
-
cpe:2.3:a:keybase:keybase:1.0.0-36
-
cpe:2.3:a:keybase:keybase:1.0.0-37
-
cpe:2.3:a:keybase:keybase:1.0.0-38
-
cpe:2.3:a:keybase:keybase:1.0.0-39
-
cpe:2.3:a:keybase:keybase:1.0.0-40
-
cpe:2.3:a:keybase:keybase:1.0.0-41
-
cpe:2.3:a:keybase:keybase:1.0.0-42
-
cpe:2.3:a:keybase:keybase:1.0.0-43
-
cpe:2.3:a:keybase:keybase:1.0.0-44
-
cpe:2.3:a:keybase:keybase:1.0.0-45
-
cpe:2.3:a:keybase:keybase:1.0.0-46
-
cpe:2.3:a:keybase:keybase:1.0.0-47
-
cpe:2.3:a:keybase:keybase:1.0.1-0
-
cpe:2.3:a:keybase:keybase:1.0.10-0
-
cpe:2.3:a:keybase:keybase:1.0.11-0
-
cpe:2.3:a:keybase:keybase:1.0.12-0
-
cpe:2.3:a:keybase:keybase:1.0.13-0
-
cpe:2.3:a:keybase:keybase:1.0.14-0
-
cpe:2.3:a:keybase:keybase:1.0.14-1
-
cpe:2.3:a:keybase:keybase:1.0.15
-
cpe:2.3:a:keybase:keybase:1.0.16
-
cpe:2.3:a:keybase:keybase:1.0.17
-
cpe:2.3:a:keybase:keybase:1.0.18
-
cpe:2.3:a:keybase:keybase:1.0.19
-
cpe:2.3:a:keybase:keybase:1.0.2-0
-
cpe:2.3:a:keybase:keybase:1.0.20
-
cpe:2.3:a:keybase:keybase:1.0.21
-
cpe:2.3:a:keybase:keybase:1.0.22
-
cpe:2.3:a:keybase:keybase:1.0.27
-
cpe:2.3:a:keybase:keybase:1.0.28
-
cpe:2.3:a:keybase:keybase:1.0.29
-
cpe:2.3:a:keybase:keybase:1.0.3-0
-
cpe:2.3:a:keybase:keybase:1.0.30
-
cpe:2.3:a:keybase:keybase:1.0.31
-
cpe:2.3:a:keybase:keybase:1.0.33
-
cpe:2.3:a:keybase:keybase:1.0.34
-
cpe:2.3:a:keybase:keybase:1.0.36
-
cpe:2.3:a:keybase:keybase:1.0.39
-
cpe:2.3:a:keybase:keybase:1.0.4-0
-
cpe:2.3:a:keybase:keybase:1.0.4-4
-
cpe:2.3:a:keybase:keybase:1.0.40
-
cpe:2.3:a:keybase:keybase:1.0.41
-
cpe:2.3:a:keybase:keybase:1.0.42
-
cpe:2.3:a:keybase:keybase:1.0.43
-
cpe:2.3:a:keybase:keybase:1.0.44
-
cpe:2.3:a:keybase:keybase:1.0.46
-
cpe:2.3:a:keybase:keybase:1.0.47
-
cpe:2.3:a:keybase:keybase:1.0.48
-
cpe:2.3:a:keybase:keybase:1.0.5-0
-
cpe:2.3:a:keybase:keybase:1.0.5-1
-
cpe:2.3:a:keybase:keybase:1.0.5-2
-
cpe:2.3:a:keybase:keybase:1.0.5-3
-
cpe:2.3:a:keybase:keybase:1.0.5-4
-
cpe:2.3:a:keybase:keybase:1.0.5-5
-
cpe:2.3:a:keybase:keybase:1.0.5-6
-
cpe:2.3:a:keybase:keybase:1.0.5-7
-
cpe:2.3:a:keybase:keybase:1.0.6-0
-
cpe:2.3:a:keybase:keybase:1.0.6-1
-
cpe:2.3:a:keybase:keybase:1.0.7-0
-
cpe:2.3:a:keybase:keybase:1.0.8-0
-
cpe:2.3:a:keybase:keybase:1.0.9-0
-
cpe:2.3:a:keybase:keybase:1.0.9-1
-
cpe:2.3:a:keybase:keybase:2.0.0
-
cpe:2.3:a:keybase:keybase:2.1.0
-
cpe:2.3:a:keybase:keybase:2.1.1
-
cpe:2.3:a:keybase:keybase:2.1.2
-
cpe:2.3:a:keybase:keybase:2.10.0
-
cpe:2.3:a:keybase:keybase:2.10.1
-
cpe:2.3:a:keybase:keybase:2.11.0
-
cpe:2.3:a:keybase:keybase:2.12.2
-
cpe:2.3:a:keybase:keybase:2.12.6
-
cpe:2.3:a:keybase:keybase:2.13.1
-
cpe:2.3:a:keybase:keybase:2.13.2
-
cpe:2.3:a:keybase:keybase:2.3.0
-
cpe:2.3:a:keybase:keybase:2.5.0
-
cpe:2.3:a:keybase:keybase:2.5.1
-
cpe:2.3:a:keybase:keybase:2.5.2
-
cpe:2.3:a:keybase:keybase:2.6.0
-
cpe:2.3:a:keybase:keybase:2.6.2
-
cpe:2.3:a:keybase:keybase:2.7.0
-
cpe:2.3:a:keybase:keybase:2.7.2
-
cpe:2.3:a:keybase:keybase:2.7.3
-
cpe:2.3:a:keybase:keybase:2.7.4
-
cpe:2.3:a:keybase:keybase:2.8.0
-
cpe:2.3:a:keybase:keybase:2.8.0-20181023124437
-
cpe:2.3:a:keybase:keybase:2.9.0
-
cpe:2.3:a:keybase:keybase:3.0.0
-
cpe:2.3:a:keybase:keybase:3.1.0
-
cpe:2.3:a:keybase:keybase:3.1.1
-
cpe:2.3:a:keybase:keybase:3.1.2
-
cpe:2.3:a:keybase:keybase:3.2.1
-
cpe:2.3:a:keybase:keybase:3.2.2
-
cpe:2.3:a:keybase:keybase:4.0.0
-
cpe:2.3:a:keybase:keybase:4.1.0
-
cpe:2.3:a:keybase:keybase:4.2.0
-
cpe:2.3:a:keybase:keybase:4.2.1
-
cpe:2.3:a:keybase:keybase:4.3.0
-
cpe:2.3:a:keybase:keybase:4.3.1
-
cpe:2.3:a:keybase:keybase:4.3.2
-
cpe:2.3:a:keybase:keybase:4.4.0
-
cpe:2.3:a:keybase:keybase:4.4.1
-
cpe:2.3:a:keybase:keybase:4.4.2
-
cpe:2.3:a:keybase:keybase:4.5.0
-
cpe:2.3:a:keybase:keybase:4.6.0
-
cpe:2.3:a:keybase:keybase:4.6.1
-
cpe:2.3:a:keybase:keybase:4.7.0
-
cpe:2.3:a:keybase:keybase:4.7.1
-
cpe:2.3:a:keybase:keybase:4.7.2
-
cpe:2.3:a:keybase:keybase:5.0.0
-
cpe:2.3:a:keybase:keybase:5.1.0
-
cpe:2.3:a:keybase:keybase:5.1.1
-
cpe:2.3:a:keybase:keybase:5.2.0
-
cpe:2.3:a:keybase:keybase:5.2.1
-
cpe:2.3:a:keybase:keybase:5.3.0
-
cpe:2.3:a:keybase:keybase:5.3.1
-
cpe:2.3:a:keybase:keybase:5.4.0
-
cpe:2.3:a:keybase:keybase:5.4.1
-
cpe:2.3:a:keybase:keybase:5.4.2
-
cpe:2.3:a:keybase:keybase:5.5.0
-
cpe:2.3:a:keybase:keybase:5.5.1
-
cpe:2.3:a:keybase:keybase:5.5.2
-
-
cpe:2.3:o:keybase:keybase:*
-
cpe:2.3:o:microsoft:windows:-
-