CVE-2016-5119: MitM Attack against KeePass 2’s Update Check

This post is about a Man in the Middle (MitM) vulnerability in KeePass 2’s automatic update check. KeePass – the free and open source password manager – uses, in all versions up to the current 2.33, unencrypted HTTP requests to check for new software versions. An attacker can abuse this automatic update check – if enabled – to “release” a new … Continue reading CVE-2016-5119: MitM Attack against KeePass 2’s Update Check