CVE-2017-8296
Estado: ModificadaAlta (7.5)—
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.40%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-522
Referencias
- http://openwall.com/lists/oss-security/2017/04/26/9
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817
- https://security.gentoo.org/glsa/201708-04
- https://sourceforge.net/p/kedpm/bugs/6/
- http://openwall.com/lists/oss-security/2017/04/26/9
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817
- https://security.gentoo.org/glsa/201708-04
- https://sourceforge.net/p/kedpm/bugs/6/
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-8296",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-04-27T15:59:00.197",
"references": [
{
"url": "http://openwall.com/lists/oss-security/2017/04/26/9",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201708-04",
"source": "cve@mitre.org"
},
{
"url": "https://sourceforge.net/p/kedpm/bugs/6/",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2017/04/26/9",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201708-04",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sourceforge.net/p/kedpm/bugs/6/",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the \"password\" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext."
},
{
"lang": "es",
"value": "kedpm en las versiones desde la 0.5 hasta la 1.0 crea un archivo histórico en ~/.kedpm/history que está escrito en texto claro. Todos los comandos ejecutados en el gestor de contraseñas se escriben en este archivo. Esto puede conducir a la divulgación de la contraseña maestra si el comando \"contraseña\" se utiliza con un argumento. Los nombres de las entradas de contraseña creadas y consultadas también son accesibles en texto claro."
}
],
"lastModified": "2026-06-17T01:26:08.767",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ked_password_manager_project:ked_password_manager:0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA192A78-6552-4738-A889-9FD7830F47C8"
},
{
"criteria": "cpe:2.3:a:ked_password_manager_project:ked_password_manager:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31211E9C-D923-4CC8-8283-98C01C60127A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}