In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-11T16:53:22.970Z
Reserved: 2023-06-19T00:00:00.000Z
Link: CVE-2023-35866
Updated: 2024-08-02T16:30:45.422Z
Status : Modified
Published: 2023-06-19T06:15:09.240
Modified: 2024-12-11T17:15:13.390
Link: CVE-2023-35866
No data.
OpenCVE Enrichment
No data.
Weaknesses