Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf2q-qxhf-rqh5

Опубликовано: 22 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

** DISPUTED ** KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

** DISPUTED ** KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

EPSS

Процентиль: 97%
0.40868
Средний

5.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 5.5
nvd
почти 3 года назад

KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

CVSS3: 5.5
fstec
около 3 лет назад

Уязвимость менеджера паролей KeePass, связанная с незашифрованным хранением критичной информации, позволяющая нарушителю получить пароли в открытом виде

CVSS3: 5.5
redos
больше 1 года назад

Уязвимость KeePass

EPSS

Процентиль: 97%
0.40868
Средний

5.5 Medium

CVSS3

Дефекты

CWE-312