Vulnerabilities > CVE-2021-34421 - Incomplete Cleanup vulnerability in Keybase 5.8.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
keybase
CWE-459

Summary

The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.

Vulnerable Configurations

Part Description Count
Application
Keybase
2

Common Weakness Enumeration (CWE)