heisec@social.heise.de - BSI warnt vor KeePassXC-Schwachstellen

Das BSI warnt vor Schwachstellen im Passwort-Manager KeePassXC. Angreifer können Dateien oder das Master-Passwort ohne Authentifzierungsrückfrage manipulieren.

[The BSI warns of vulnerabilities in the password manager KeePassXC. Attackers can manipulate files or the master password without authentication confirmation.]

all 20 comments

sorted by: hot top controversial new old
[–] 6 points 3 years ago* (last edited 3 years ago) (2 children)

KeePassXC is not affected by this vulnerability.

  • source
  • hideshow 4 child comments
  • [–] 1 point 3 years ago (1 child)

    This is also the vulnerability that made many people delete Keepass 2 for XC many months ago so it is very strange that they make an article that sounds like it's a new vulnerability.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 3 years ago* (last edited 3 years ago) (1 child)

    Can't read German. What is required to perform this attack?

  • source
  • hideshow 2 child comments
  • [–] 3 points 3 years ago (1 child)

    Ok I checked it up (CVE-2023-35866). It basically says an attacker may export everything if they have access to your unlocked database. Which seems... obvious? The project contributors says it's not a vulnerability which I incline to agree.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 3 years ago

    Here is KeePassXC's response: https://keepassxc.org/blog/2023-06-20-cve-202335866

    Basically some random guy with weird misconceptions about security decided this was an issue, it's obviously not. Honestly concerning that he was able to easily get a CVE for this and even get articles about it published on some websites.

  • source
  • [–] 2 points 3 years ago

    Lock the pc, if you leave and lock the db, if pc is locked, lid is closed and this is absolute a non-issue.

    German BSI is sometimes a little bit over motivated ;-)

  • source
  • [–] 1 point 3 years ago (3 children)

    Why is there no link to the article?

  • source
  • hideshow 6 child comments
  • [+] 1 point 3 years ago (1 child)
  • [–] 2 points 3 years ago (2 children)

    It's a denial of service vulnerability. Requiring the existing master password to change the master password will stop a drive by miscreant denying you access to your db. And password change system I've ever used has required the existing password to he entered first.

    Likewise a full db export feel like a big enough deal to require authorization.

    If you're careful and lock your machine when you leave it then you should be pretty safe. I'm surprised these aren't already features.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 3 years ago (1 child)

    No, requiring the existing master password won't help. A drive by miscreant with access to an unlocked computer with an unlocked DB can delete all the DB entries. If the DB is locked they can just delete the DB file. KeePassXC can't defend against this, that takes properly functioning versioned backups.

  • source
  • parent
  • hideshow 2 child comments