10
CVE-2018-1000835
- EPSS 1.8%
- Veröffentlicht 20.12.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:27
- Erkennungen
KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta1
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta10
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta11
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta12
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta13
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta14
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta15
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta16
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta17
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta2
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta3
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta4
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta5
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta6
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta7
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta8
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.8% | 0.756 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://0dd.zone/2018/10/28/KeePassDX-XXE/
https://github.com/Kunzisoft/KeePassDX/issues/200