Kunzisoft / KeePassDX

Lightweight vault and password manager for Android, KeePassDX allows editing encrypted data in a single file in KeePass format and fill in the forms in a secure way.
https://www.keepassdx.com/
GNU General Public License v3.0
4.29k stars 260 forks source link

a security hole #1805

Closed wfhyu closed 2 months ago

wfhyu commented 2 months ago

when using kreepass. for Android 4.0.5 if I make à copy of password I see the password in the clipboard even after closing keepass. So it can be dangers. password should be cleared.

A clear and concise description of what the bug is.

To Reproduce

Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Expected behavior

A clear and concise description of what you expected to happen.

KeePass Database

KeePassDX:

Android:

Additional context

Add any other context about the problem here.

J-Jamet commented 2 months ago

It's your system that keeps track of clipbloard items, a dialog box explains this in KeePassDX and you have to accept the risks, which you have done. To deactivate the feature, go to Settings -> Form filling -> Clipboard trust

https://github.com/Kunzisoft/KeePassDX/wiki/Clipboard