Bugzilla – Bug 1212518
VUL-0: DISPUTED: CVE-2023-35866: keepassxc: local attacker can make changes to the Database security settings
Last modified: 2023-06-20 14:16:50 UTC
CVE-2023-35866 In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35866 https://www.cve.org/CVERecord?id=CVE-2023-35866 https://github.com/keepassxreboot/keepassxc/issues/9339 https://github.com/keepassxreboot/keepassxc/issues/9391
looks like there is no fix
JFYI: upstream rejected this bug and is asking for the CVE to be retracted. see discussion in 9339