CVE-2023-28686

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/03/2023
Last modified:
19/02/2025

Description

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dino:dino:*:*:*:*:*:*:*:* 0.2.3 (excluding)
cpe:2.3:a:dino:dino:*:*:*:*:*:*:*:* 0.3.0 (including) 0.3.2 (excluding)
cpe:2.3:a:dino:dino:*:*:*:*:*:*:*:* 0.4.0 (including) 0.4.2 (excluding)
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*