PhilippC / PhilippC/keepass2android
[QUESTION] Potential Security Risk with AutoOpen URLs Containing Cleartext Credentials?
Nobody has claimed this yet.
- Dominant language
- C#
- Stars
- 6.2k
- Forks
- 478
- Avg merge
- 1h 4m
- Merged PRs (30d)
- 2
Description
Version: 1.10-pre
I am using Keepass2Android and generally find it very useful. However, I have a concern regarding the AutoOpen feature. When I create a child database and link it via WebDAV, the AutoOpen entry in the parent database contains the URL to the child database with the username and password in cleartext.
Does the presence of cleartext credentials in the URL pose a security risk when Keepass2Android establishes the connection to the child database? Specifically, I am worried about potential vulnerabilities during the transmission or storage of these credentials.
Thanks for any Help!
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue concerns AutoOpen child-database connections through WebDAV and credentials embedded in the URL. Start by tracing how AutoOpen constructs and uses that URL, then assess whether credentials may be exposed during transmission or storage. Done means documenting the security impact and a clearly scoped remediation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100