PT-2023-8873 · Keepassxc+1 · Keepassxc+1

Cyberctzn

·

Publicado

2023-04-20

·

Atualizado

2024-12-11

·

CVE-2023-35866

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions KeePassXC versions 2.7.5 and earlier
Description A local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. The vendor's position is that asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker.
Recommendations For KeePassXC versions 2.7.5 and earlier, as a temporary workaround, consider restricting access to the Database security settings until a patch is available. Avoid making changes to the master password and second-factor authentication without proper authentication.

Correção

Improper Authentication

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-8414
BDU:2024-02513
CVE-2023-35866

Produtos afetados

Alt Linux
Keepassxc