{"id":"CVE-2024-33900","details":"KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.","modified":"2026-04-10T05:12:44.457770Z","published":"2024-05-20T21:15:09.177Z","references":[{"type":"ADVISORY","url":"https://keepassxc.org/blog/"},{"type":"REPORT","url":"https://github.com/keepassxreboot/keepassxc/issues/10784"},{"type":"ARTICLE","url":"https://keepassxc.org/blog/2019-02-21-memory-security/"},{"type":"EVIDENCE","url":"https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keepassxreboot/keepassxc","events":[{"introduced":"0"},{"last_affected":"68e2dd8d22fdef79c72ad5902e026c698e2ff087"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.7.7"}]}}],"versions":["2.0-alpha1","2.0-alpha2","2.0-alpha3","2.0-alpha4","2.0-alpha5","2.0-alpha6","2.0.3-http","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-33900.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"}]}