gist.github.com
https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838 CVE-2024-33901
MEDIUM
Record summary
CVE-2024-33901 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC.
Description
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 29, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
keepassxcBrowse keepassxc / keepassxcDefault status: affected | CVE List | 2.7.7 | affected |
Proofs of concept
1Repository PoCs
GitHubgmikisilva/CVE-2024-33901-ProofOfConceptRepository PoCby gmikisilvaStars: 2Not analyzed4 files
References
5github.com
https://github.com/keepassxreboot/keepassxc/issues/10784 keepassxc.org
https://keepassxc.org/blog keepassxc.org
https://keepassxc.org/blog/2019-02-21-memory-security nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33901