CVE-2022-0725Sensitive Information Exposure in Keepass

Severity
7.5HIGHNVD
EPSS
1.1%
top 21.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMar 11

Description

A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5keepass/keepassno fix available
NVDkeepass/keepass2.48

Also affects: Fedora 35

🔴Vulnerability Details

2
GHSA
GHSA-4p6x-85ff-qrhc: A flaw was found in KeePass2022-03-11
OSV
CVE-2022-0725: A flaw was found in keepass2022-03-10
CVE-2022-0725 — Sensitive Information Exposure | cvebase