CVE-2023-24055

Source
https://cve.org/CVERecord?id=CVE-2023-24055
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24055.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-24055
Related
Published
2023-01-22T04:15:11.560Z
Modified
2026-03-15T22:46:27.730742Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24055.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2.53"
            }
        ]
    }
]