OSV 1.4.0 · unreviewed · 修改于 2026-09-03 05:32
发布时间
2026-09-03 05:32
GitHub 审查时间
—
NVD 发布时间
2026-09-03 04:17
源文件
advisories/unreviewed/2026/09/GHSA-qgm4-q464-4557/GHSA-qgm4-q464-4557.json
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.
该公告没有提供结构化的受影响软件包信息。