Bugzilla – Bug 1224789
VUL-0: CVE-2024-33900: keepassxc: recovery of cleartext credentials
Last modified: 2024-05-22 13:51:29 UTC
KeePassXC 2.7.7 allows attackers to recover cleartext credentials. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-33900 https://www.cve.org/CVERecord?id=CVE-2024-33900 https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838 https://keepassxc.org/blog/
Closing this bug as RESOLVED/WONTFIX, as it is unlikely this issue will be fixed by upstream. There are hardening measures implemented to mitigate the problem, but solving it completely would require a solution involving more than changes to just keepassxc. See [0] for more information. [0] https://github.com/keepassxreboot/keepassxc/issues/10784