Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 13 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Keepassxc
Keepassxc keepassxc
CPEs cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*
Vendors & Products Keepassxc
Keepassxc keepassxc

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-13T15:53:01.159Z

Reserved: 2024-04-28T00:00:00.000Z

Link: CVE-2024-33901

cve-icon Vulnrichment

Updated: 2024-08-02T02:42:59.651Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-20T21:15:09.243

Modified: 2025-06-13T16:13:44.500

Link: CVE-2024-33901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.