UBUNTU-CVE-2023-35866

Source
https://ubuntu.com/security/CVE-2023-35866
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-35866.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-35866
Withdrawn
2025-06-23T15:56:53Z
Published
2023-06-19T06:15:00Z
Modified
2023-06-19T06:15:00Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

** DISPUTED ** In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."

References

Affected packages

Ubuntu:Pro:18.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.2-1
2.2.3+dfsg.1-1
2.2.4+dfsg.1-1
2.3.0+dfsg.1-0ubuntu2
2.3.1+dfsg.1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-35866.json"

Ubuntu:20.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.3+dfsg.1-1
2.4.3+dfsg.1-1build1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-35866.json"

Ubuntu:22.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.6+dfsg.1-1~exp1
2.6.6+dfsg.1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-35866.json"

Ubuntu:24.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.4+dfsg.1-2
2.7.6+dfsg.1-1
2.7.6+dfsg.1-1build2
2.7.6+dfsg.1-1build3

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-35866.json"