Описание
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.
Ссылки
- ExploitTechnical Description
- Third Party Advisory
- PatchProduct
- ExploitTechnical Description
- Third Party Advisory
- PatchProduct
Уязвимые конфигурации
Конфигурация 1Версия до 2.33 (включая)
cpe:2.3:a:keepass:keepass:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.0026
Низкий
7.5 High
CVSS3
5.1 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 9 лет назад
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.
CVSS3: 7.5
debian
около 9 лет назад
The automatic update feature in KeePass 2.33 and earlier allows man-in ...
CVSS3: 7.5
github
больше 3 лет назад
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.
EPSS
Процентиль: 49%
0.0026
Низкий
7.5 High
CVSS3
5.1 Medium
CVSS2
Дефекты
CWE-20