{"id":"CVE-2024-33900","details":"KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.","modified":"2026-08-12T03:51:36.211155799Z","published":"2024-05-20T20:29:54.072Z","database_specific":{"cna_assigner":"mitre","isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/33xxx/CVE-2024-33900.json"},"references":[{"type":"WEB","url":"https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/33xxx/CVE-2024-33900.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33900"},{"type":"REPORT","url":"https://github.com/keepassxreboot/keepassxc/issues/10784"},{"type":"ARTICLE","url":"https://keepassxc.org/blog/"},{"type":"ARTICLE","url":"https://keepassxc.org/blog/2019-02-21-memory-security/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keepassxreboot/keepassxc","events":[{"introduced":"68e2dd8d22fdef79c72ad5902e026c698e2ff087"},{"last_affected":"68e2dd8d22fdef79c72ad5902e026c698e2ff087"}],"database_specific":{"cpe":"cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.7.7"},{"last_affected":"2.7.7"}],"source":"CPE_STRING"}}],"versions":["2.7.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-33900.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"}]}