📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

KeePass Password Safe 2 Dominik Reichl

KeePass Password Safe 2 2.59

Latest tracked version 2.59. Release status, tracked CVEs, and automated cross-platform patching for KeePass Password Safe 2.

Category: Password Managers

PlatformLatest versionCVEs trackedLast checked
Windows2.5972024-09-26

Known vulnerabilities (CVEs) in KeePass Password Safe 2

Lavawall tracks 7 published CVEs affecting KeePass Password Safe 2, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2023-327842023-05-15 06:15:10HIGH (8)In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation.NETWORK
CVE-2023-240552023-01-22 04:15:12MEDIUM (6)KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.LOCAL
CVE-2022-07252022-03-10 17:44:57HIGH (8)A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.NETWORK
CVE-2019-201842020-01-09 22:15:13HIGH (8)KeePass 2.4.1 allows CSV injection in the title field of a CSV export.LOCAL
CVE-2017-1000062017-07-17 13:18:18MEDIUM (5)The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information.NETWORK
CVE-2016-51192017-01-23 21:59:02MEDIUM (5)The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.NETWORK
CVE-2010-52002012-09-06 10:41:55MEDIUM (7)Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .kdb file. NOTE: some of these details are obtained from third party information.LOCAL

Why keeping KeePass Password Safe 2 patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every KeePass Password Safe 2 release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches KeePass Password Safe 2

Lavawall® watches KeePass Password Safe 2 releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on KeePass Password Safe 2, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of KeePass Password Safe 2?
Lavawall tracks KeePass Password Safe 2 at version 2.59 (last checked 2024-09-26). New releases are monitored continuously and can be deployed automatically across your fleet.
Does KeePass Password Safe 2 have known security vulnerabilities (CVEs)?
Lavawall tracks 7 CVEs for KeePass Password Safe 2 and remediates them automatically as part of patching.
How do I patch KeePass Password Safe 2 automatically?
Deploy the Lavawall® agent and KeePass Password Safe 2 updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for KeePass Password Safe 2 through public information and proprietary statistical analysis, and can patch it automatically across your fleet.