PT-2022-7125 · Keepass+2 · Keepass+3

Chris

·

Published

2022-12-09

·

Updated

2025-01-30

·

CVE-2023-24055

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KeePass versions 2.53 and earlier KeePass through 2.53 (in a default installation)
Description The issue is related to the storage of critical information in an unencrypted manner. An attacker with write access to the XML configuration file can obtain cleartext passwords by adding an export trigger. The vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC. Researchers argue that this is a security flaw, as no action is required from the KeePass owner to export passwords, making it impossible even in situations where an actor gains access to the device.
Recommendations For KeePass versions 2.53 and earlier, consider disabling the export trigger feature to prevent exploitation until a patch is available. For KeePass through 2.53 (in a default installation), restrict access to the XML configuration file to minimize the risk of exploitation. As a temporary workaround, consider downgrading the executable to a version that does not contain the vulnerable export trigger feature, but be aware that this may introduce other security risks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2101
ALT-PU-2023-4128
ALT-PU-2023-5166
ALT-PU-2024-12934
ALT-PU-2025-2135
BDU:2023-07674
CVE-2023-24055
MGASA-2023-0221

Affected Products

Alt Linux
Keepass
Keepass2
Red Os