Patch & vulnerability status
Dominik Reichl
KeePass Password Safe 2 2.59
Latest tracked version 2.59. Release status, tracked CVEs, and automated cross-platform patching for KeePass Password Safe 2.
Category: Password Managers
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 2.59 | 7 | 2024-09-26 |
Known vulnerabilities (CVEs) in KeePass Password Safe 2
Lavawall tracks 7 published CVEs affecting KeePass Password Safe 2, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2023-32784 | 2023-05-15 06:15:10 | HIGH (8) | In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation. | NETWORK |
| CVE-2023-24055 | 2023-01-22 04:15:12 | MEDIUM (6) | KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC. | LOCAL |
| CVE-2022-0725 | 2022-03-10 17:44:57 | HIGH (8) | A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs. | NETWORK |
| CVE-2019-20184 | 2020-01-09 22:15:13 | HIGH (8) | KeePass 2.4.1 allows CSV injection in the title field of a CSV export. | LOCAL |
| CVE-2017-100006 | 2017-07-17 13:18:18 | MEDIUM (5) | The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information. | NETWORK |
| CVE-2016-5119 | 2017-01-23 21:59:02 | MEDIUM (5) | The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update. | NETWORK |
| CVE-2010-5200 | 2012-09-06 10:41:55 | MEDIUM (7) | Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .kdb file. NOTE: some of these details are obtained from third party information. | LOCAL |
Why keeping KeePass Password Safe 2 patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every KeePass Password Safe 2 release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches KeePass Password Safe 2
Lavawall® watches KeePass Password Safe 2 releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on KeePass Password Safe 2, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks KeePass Password Safe 2 at version 2.59 (last checked 2024-09-26). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 7 CVEs for KeePass Password Safe 2 and remediates them automatically as part of patching.
Deploy the Lavawall® agent and KeePass Password Safe 2 updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for KeePass Password Safe 2 through public information and proprietary statistical analysis, and can patch it automatically across your fleet.