CVE-2024-33901

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*

History

13 Jun 2025, 16:13

Type Values Removed Values Added
First Time Keepassxc keepassxc
Keepassxc
References () https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838 - () https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838 - Exploit
References () https://github.com/keepassxreboot/keepassxc/issues/10784 - () https://github.com/keepassxreboot/keepassxc/issues/10784 - Issue Tracking
References () https://keepassxc.org/blog/ - () https://keepassxc.org/blog/ - Release Notes
References () https://keepassxc.org/blog/2019-02-21-memory-security/ - () https://keepassxc.org/blog/2019-02-21-memory-security/ - Product
CPE cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*

Information

Published : 2024-05-20 21:15

Updated : 2025-06-13 16:13


NVD link : CVE-2024-33901

Mitre link : CVE-2024-33901

CVE.ORG link : CVE-2024-33901


JSON object : View

Products Affected

keepassxc

  • keepassxc
CWE
CWE-316

Cleartext Storage of Sensitive Information in Memory