CVE-2017-8296 - CVE House
Back to Database
Status published High CVE-2017-8296

kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history...

Vulnerability Description

kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-8296

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

ked password manager project

View all reports →

Affected Software

ked password manager
Vulnerable Versions:
0.5, 1.0

Timeline

Official Publish: April 27th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.