Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-35866

Опубликовано: 19 июн. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 5.5

Описание

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

disputed
esm-apps/bionic

not-affected

disputed
esm-apps/focal

not-affected

disputed
esm-apps/jammy

not-affected

disputed
esm-apps/noble

not-affected

disputed
focal

not-affected

disputed
jammy

not-affected

disputed
kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage

Показывать по

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."

CVSS3: 5.5
debian
больше 2 лет назад

In KeePassXC through 2.7.5, a local attacker can make changes to the D ...

CVSS3: 5.5
github
больше 2 лет назад

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes.

CVSS3: 5.5
fstec
почти 3 года назад

Уязвимость компонента Setting Handler менеджера паролей KeePassXC, позволяющая нарушителю обойти существующие ограничения безопасности

5.5 Medium

CVSS3