5 comments

[ 3.0 ms ] story [ 25.7 ms ] thread
This isn't a vulnerability. This is like saying that it's a vulnerability in your door lock that if you leave your door open instead of locking it, bad guys can come in your house.
If the vault is open, a script could read and save all passwords. Export is a user convenience feature.

This is a vulnerability that requires the plaintext, hence a bit of a joke!

Or am I missing something? (I didn’t read past the initial paragraphs).

not a random website: https://nvd.nist.gov/vuln/detail/CVE-2023-35866

> In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes.

"within an authenticated DB session"

A blog post has been put up to address this: https://keepassxc.org/blog/2023-06-20-cve-202335866/

Additionally, this is certainly not unique to KeePassXC. KeePass original and other clones we have tested do not require entering your credentials again prior to export or credential change.

I am a happy keepassxc user but I have criticized the authors on multiple occasions for not investing in a clear documentation of an attacker model. It seems to me a lot of bogus security is added here and there and this non-CVE is the result, because people demand more of that.