Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf2q-qxhf-rqh5

Опубликовано: 22 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

** DISPUTED ** KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

** DISPUTED ** KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

EPSS

Процентиль: 97%
0.35331
Средний

5.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

CVSS3: 5.5
fstec
больше 2 лет назад

Уязвимость менеджера паролей KeePass, связанная с незашифрованным хранением критичной информации, позволяющая нарушителю получить пароли в открытом виде

CVSS3: 5.5
redos
10 месяцев назад

Уязвимость KeePass

EPSS

Процентиль: 97%
0.35331
Средний

5.5 Medium

CVSS3

Дефекты

CWE-312