# KeePass

**URL:** https://discuss.privacyguides.net/t/keepass/11456
**Category:** Tool Suggestions
**Created:** 2023-01-10T19:54:34Z
**Posts:** 14
**Showing post:** 5 of 14

## Post 5 by @SuperJohn — 2023-05-21T19:49:46Z

Another reason not to use KeePass:  
This CVE from January 2023

> **[CVE -
CVE-2023-24055](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24055)**
>
> The mission of the CVE™ Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

So an attacker with write access to the KeePass XML configuration file, can trigger a cleartext password export on startup. And the lead developer refuses to fix it.

[https://securityboulevard.com/2023/01/keepass-password-manager-leak-cve-richixbw/](https://securityboulevard.com/2023/01/keepass-password-manager-leak-cve-richixbw/)

> **[KeePass / Discussion /
  Open Discussion: someone can read the passwords...](https://sourceforge.net/p/keepass/discussion/329220/thread/a146e5cf6b/)**

> **[KeePass / Feature Requests / #2773 Improve the security of password exports](https://sourceforge.net/p/keepass/feature-requests/2773/)**

---

_[View the full topic](https://discuss.privacyguides.net/t/keepass/11456)._
