PT-2023-8873 · Keepassxc+1 · Keepassxc+1
Cyberctzn
·
Publicado
2023-04-20
·
Atualizado
2024-12-11
·
CVE-2023-35866
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
KeePassXC versions 2.7.5 and earlier
Description
A local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. The vendor's position is that asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker.
Recommendations
For KeePassXC versions 2.7.5 and earlier, as a temporary workaround, consider restricting access to the Database security settings until a patch is available. Avoid making changes to the master password and second-factor authentication without proper authentication.
Correção
Improper Authentication
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Keepassxc