CVE-2024-33901
Last modified
CVE-2024-33901 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Keepassxc | Keepassxc | 2.7.7 |
References
- https://github.com/keepassxreboot/keepassxc/issues/10784Issue Tracking
- https://keepassxc.org/blog/Release Notes
- https://github.com/keepassxreboot/keepassxc/issues/10784Issue Tracking
- https://keepassxc.org/blog/Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33901?
How severe is CVE-2024-33901?
How do I fix CVE-2024-33901?
Are you affected by CVE-2024-33901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
