{"id":"MGASA-2023-0221","summary":"Updated keepass packages fix security vulnerability","details":"Allows an attacker, who has write access to the XML configuration file, to\nobtain the cleartext passwords by adding an export trigger. Disputed by\nvendor due to level of access required. (CVE-2023-24055)\nPossible to recover the cleartext master password from a memory dump, even\nwhen a workspace is locked or no longer running (CVE-2023-32784)\n","modified":"2026-04-16T04:43:28.557993087Z","published":"2023-07-07T05:54:45Z","upstream":["CVE-2023-24055","CVE-2023-32784"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0221.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31935"},{"type":"WEB","url":"https://amp.thehackernews.com/thn/2023/05/keepass-exploit-allows-attackers-to.html"}],"affected":[{"package":{"name":"keepass","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/keepass?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.54-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0221.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}