10

CVE-2018-1000835

KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta1
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta10
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta11
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta12
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta13
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta14
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta15
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta16
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta17
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta2
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta3
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta4
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta5
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta6
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta7
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta8
Keepassdx ≫ Keepass Dx Version 2.5.0.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.756
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://0dd.zone/2018/10/28/KeePassDX-XXE/
Third Party Advisory
https://github.com/Kunzisoft/KeePassDX/issues/200
Third Party Advisory
Issue Tracking