CVE-2023-28686
published 2023-03-24CVE-2023-28686: Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can…
PriorityP431high7.1CVSS 3.1
AVNACLPRNUIRSUCHILAN
EPSS
0.70%
49.0th percentile
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dino-im | < dino-im 0.4.2-1 (bookworm) | dino-im 0.4.2-1 (bookworm) |
| dino | dino | < 0.2.3 | 0.2.3 |
| dino | dino | >= 0.3.0 < 0.3.2 | 0.3.2 |
| dino | dino | >= 0.4.0 < 0.4.2 | 0.4.2 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
osv7.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xxch-mf4j-qcvj: Dino before 0
ghsa_unreviewed·2023-03-24
CVE-2023-28686 [HIGH] CWE-639 GHSA-xxch-mf4j-qcvj: Dino before 0
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
OSV
CVE-2023-28686: Dino before 0
osv·2023-03-24·CVSS 7.1
CVE-2023-28686 [HIGH] CVE-2023-28686: Dino before 0
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Ubuntu
Dino vulnerability
vendor_ubuntu·2025-04-09
CVE-2023-28686 Dino vulnerability
Title: Dino vulnerability
Summary: Dino could be made to expose sensitive information over the
network.
Kim Alvefur discovered that Dino did not correctly sanitize certain
messages. A remote attacker could possibly use this issue to leak
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-28686: dino-im - Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers t...
vendor_debian·2023·CVSS 7.1
CVE-2023-28686 [HIGH] CVE-2023-28686: dino-im - Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers t...
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Scope: local
bookworm: resolved (fixed in 0.4.2-1)
bullseye: resolved (fixed in 0.2.0-3+deb11u1)
forky: resolved (fixed in 0.4.2-1)
sid: resolved (fixed in 0.4.2-1)
trixie: resolved (fixed in 0.4.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://dino.im/security/cve-2023-28686/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQLCEUZS5GPHUQMS7C6W2NS3PHYUFHYF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GOH6NYTLPM52MDIR2IRVUR3REDVWZV6N/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IIWXAK656EHSRIRUHLPBE3AX2I4TMH7M/https://www.debian.org/security/2023/dsa-5379https://dino.im/security/cve-2023-28686/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQLCEUZS5GPHUQMS7C6W2NS3PHYUFHYF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GOH6NYTLPM52MDIR2IRVUR3REDVWZV6N/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IIWXAK656EHSRIRUHLPBE3AX2I4TMH7M/https://www.debian.org/security/2023/dsa-5379
2023-03-24
Published