CVE-2024-33901

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*

History

13 Jun 2025, 16:13

Type Values Removed Values Added
References () https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838 - () https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838 - Exploit
References () https://github.com/keepassxreboot/keepassxc/issues/10784 - () https://github.com/keepassxreboot/keepassxc/issues/10784 - Issue Tracking
References () https://keepassxc.org/blog/ - () https://keepassxc.org/blog/ - Release Notes
References () https://keepassxc.org/blog/2019-02-21-memory-security/ - () https://keepassxc.org/blog/2019-02-21-memory-security/ - Product
CPE cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*
First Time Keepassxc keepassxc
Keepassxc

21 May 2024, 17:15

Type Values Removed Values Added
References
  • () https://keepassxc.org/blog/2019-02-21-memory-security/ -
  • () https://github.com/keepassxreboot/keepassxc/issues/10784 -
Summary Issue in KeePassXC 2.7.7 allows an attacker to recover some passwords stored in the .kdbx database. Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

20 May 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-20 21:15

Updated : 2025-06-13 16:13


NVD link : CVE-2024-33901

Mitre link : CVE-2024-33901


JSON object : View

Products Affected

keepassxc

  • keepassxc
CWE

No CWE.