PT-2022-7125 · Keepass+2 · Keepass+3
Chris
·
Published
2022-12-09
·
Updated
2025-01-30
·
CVE-2023-24055
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
KeePass versions 2.53 and earlier
KeePass through 2.53 (in a default installation)
Description
The issue is related to the storage of critical information in an unencrypted manner. An attacker with write access to the XML configuration file can obtain cleartext passwords by adding an export trigger. The vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC. Researchers argue that this is a security flaw, as no action is required from the KeePass owner to export passwords, making it impossible even in situations where an actor gains access to the device.
Recommendations
For KeePass versions 2.53 and earlier, consider disabling the export trigger feature to prevent exploitation until a patch is available.
For KeePass through 2.53 (in a default installation), restrict access to the XML configuration file to minimize the risk of exploitation.
As a temporary workaround, consider downgrading the executable to a version that does not contain the vulnerable export trigger feature, but be aware that this may introduce other security risks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Keepass
Keepass2
Red Os