vulnerability
FreeBSD: VID-851ce3e4-8b03-11ef-84e9-901b0e9408dc (CVE-2024-47779): element-web -- Potential exposure of access token via authenticated media
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:L/Au:N/C:C/I:C/A:N) | Oct 15, 2024 | Oct 17, 2024 | Dec 10, 2025 |
Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Oct 15, 2024
Added
Oct 17, 2024
Modified
Dec 10, 2025
Description
Element team reports: Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue.
Solution
freebsd-upgrade-package-element-web
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.