keybase records
8 published records for vendor keybase.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-426 Untrusted Search Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-7249No exploit | In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one usekeybase · keybase · CWE-367 | Critical9.8 | — | 2.5% | Jan 31, 2019 |
36Monitor | CVE-2021-34422No exploit | Path traversal of file names in Keybase Client for Windowskeybase · keybase · CWE-22 | Critical9.0 | — | 1.4% | Nov 11, 2021 |
31Monitor | CVE-2018-18629Proof of concept | An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux.keybase · keybase · CWE-426 | High7.8 | — | 1.5% | Dec 20, 2018 |
31Monitor | CVE-2021-34426No exploit | Arbitrary command execution in Keybase Client for Windowskeybase · keybase | High7.8 | — | 0.2% | Dec 14, 2021 |
30Monitor | CVE-2019-16992No exploit | The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocukeybase · keybase · CWE-347 | High7.5 | — | 0.9% | Sep 29, 2019 |
22Monitor | CVE-2021-23827No exploit | Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive medikeybase · keybase · CWE-312 | Medium5.5 | — | 0.3% | Feb 22, 2021 |
17Monitor | CVE-2021-34421No exploit | Retained exploded messages in Keybase Clients for Android and iOSkeybase · keybase · CWE-459 | Medium4.3 | — | 0.7% | Nov 11, 2021 |
14Monitor | CVE-2022-22779No exploit | Retained exploded messages in Keybase clients for macOS and Windowskeybase · keybase · CWE-212 | Low3.7 | — | 0.8% | Feb 9, 2022 |
- CVE-2019-724940Plan
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one use
CriticalCVSS 9.8No exploitEPSS 3%keybase · keybaseJan 31, 2019
- CVE-2021-3442236Monitor
Path traversal of file names in Keybase Client for Windows
CriticalCVSS 9.0No exploitEPSS 1%keybase · keybaseNov 11, 2021
- CVE-2018-1862931Monitor
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux.
HighCVSS 7.8Proof of conceptEPSS 1%keybase · keybaseDec 20, 2018
- CVE-2021-3442631Monitor
Arbitrary command execution in Keybase Client for Windows
HighCVSS 7.8No exploitEPSS 0%keybase · keybaseDec 14, 2021
- CVE-2019-1699230Monitor
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocu
HighCVSS 7.5No exploitEPSS 1%keybase · keybaseSep 29, 2019
- CVE-2021-2382722Monitor
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive medi
MediumCVSS 5.5No exploitEPSS 0%keybase · keybaseFeb 22, 2021
- CVE-2021-3442117Monitor
Retained exploded messages in Keybase Clients for Android and iOS
MediumCVSS 4.3No exploitEPSS 1%keybase · keybaseNov 11, 2021
- CVE-2022-2277914Monitor
Retained exploded messages in Keybase clients for macOS and Windows
LowCVSS 3.7No exploitEPSS 1%keybase · keybaseFeb 9, 2022