QID 378501
Date Published: 2023-05-25
QID 378501: KeePass 2.X Master Password Retrieval Vulnerability (CVE-2023-32784)
KeePass is a modern, secure, and open-source password manager that stores and manages most sensitive information. KeePass helps storing Passwords in an encrypted database, which can be unlocked with one master key. It works for Windows, macOS, and Linux systems.
Affected Versions:
KeePass version 2.x before 2.54
QID Detection Logic (Authenticated):
On Windows, this QID looks for the vulnerable versions of KeePass by reading the KeePass related key values pairs under the registry "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall" and/or "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall"
This vulnerability in KeePass (password manager tool) enables a potential attacker with local access to obtain a plaintext master password from a user workspace.
- CVE-2023-32784 -
github.com/vdohney/keepass-password-dumper
CVEs related to QID 378501
| Advisory ID | Software | Component | Link |
|---|