Keybase是一套基于PGP技术的、支持端到端加密的社交网络平台。 Keybase Client for Android 5.8.0之前版本和Keybase Client for iOS 5.8.0之前版本存在信息泄露漏洞,该漏洞源于客户端无法正确删除用户启动消息。这可能会导致泄露本应从客户设备上删除的敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Video Communications Inc | Keybase Client for Android | unspecified ~ 5.8.0 | - |
|
| Zoom Video Communications Inc | Keybase Client for iOS | unspecified ~ 5.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-34417 | 7.9 HIGH | Authenticated remote command execution with root privileges via web console in MMR |
| CVE-2021-34422 | 7.2 HIGH | Path traversal of file names in Keybase Client for Windows |
| CVE-2021-34420 | 4.7 MEDIUM | Zoom Windows installation executable signature bypass |
| CVE-2021-34418 | 4.0 MEDIUM | Pre-auth Null pointer crash in on-premise web console |
| CVE-2021-34419 | 3.7 LOW | HTML injection in Zoom Linux client |
No comments yet