PT-2024-25537 · Keepassxc · Keepassxc

Staypirate

·

Published

2024-05-20

·

Updated

2024-08-02

·

CVE-2024-33901

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KeePassXC version 2.7.7
Description The issue allows an attacker, who has the privileges of the victim, to recover some passwords stored in the .kdbx database via a memory dump. The vendor disputes this, citing memory-management constraints that make this unavoidable in the current design and other realistic designs.
Recommendations For KeePassXC version 2.7.7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2024-33901

Affected Products

Keepassxc