{"id":"CVE-2024-33901","details":"Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.","modified":"2026-08-12T03:51:15.227448676Z","published":"2024-05-20T20:21:40.789Z","database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/33xxx/CVE-2024-33901.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/33xxx/CVE-2024-33901.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33901"},{"type":"REPORT","url":"https://github.com/keepassxreboot/keepassxc/issues/10784"},{"type":"ARTICLE","url":"https://keepassxc.org/blog/"},{"type":"ARTICLE","url":"https://keepassxc.org/blog/2019-02-21-memory-security/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keepassxreboot/keepassxc","events":[{"introduced":"68e2dd8d22fdef79c72ad5902e026c698e2ff087"},{"last_affected":"68e2dd8d22fdef79c72ad5902e026c698e2ff087"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:keepassxc:keepassxc:2.7.7:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.7.7"},{"last_affected":"2.7.7"}]}}],"versions":["2.7.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-33901.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}