Command Palette

Search for a command to run...

Bundle Report

com-kunzisoft-keepass-libre v4.4.3

Bundle risk58medium
Binary-only · L1Live analyzer output · not mock dataAnalyzed just now

v4.4.3build 44300medium· 58

85c95fb0e2cda5cdacc7f5bca360e3384e444de19bdffdf0d806b679bb612c18

Platform
Android · APK
Bundle size
15.8 MB
OS range
Android API 19 → Android API 35
Architectures
arm64-v8a, armeabi-v7a, x86, x86_64
Permissions
10

Store review readiness

Expected to pass review

All known pre-review checks pass.

Submit. All known pre-review checks pass. Reviewer may still raise non-static-analysis concerns (screenshots, metadata, UX) — those are out of scope here.

Blocking0

No pre-review rejection causes

None detected
Needs review0

No reviewer-flag items

None detected
OK4

What was checked and passed

  • Data Safety form covers SDK-collected data categories
  • Data Safety form covers third-party sharing
  • No version-confirmed CVEs against bundled SDKs
  • Static surface clusters with labeled-clean corpus neighbors· corpus k-NN bad-neighbor weight 0.20 (low)
33 findings
  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-2j2x-hx4g-2gf4 — In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-4446-656p-f54g — Deserialization of Untrusted Data in Bouncy castle

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-4h8f-2wvx-gg5w — Bouncy Castle Java Cryptography API vulnerable to DNS poisoning

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-4mv7-cq75-3qjm — Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-4vhj-98r6-424h — In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-6xx3-rg99-gc3p — Timing based private key exposure in Bouncy Castle

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-72m5-fvvv-55m6 — Observable Differences in Behavior to Error Inputs in Bouncy Castle

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-73xv-w5gp-frxh — Logic error in Legion of the Bouncy Castle BC Java

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-8353-fgcr-xfhx — Improper Input Validation in Bouncy Castle

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-8477-3v39-ggpm — Improper Validation of Integrity Check Value in Bouncy Castle

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-8xfc-gm6g-vgpv — Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-9gp4-qrff-c648 — Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-c8xf-m4ff-jcxj — Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-fjqm-246c-mwqg — In Bouncy Castle JCE Provider the other party DH public key is not fully validated

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-hr8g-6v94-x4m9 — Bouncy Castle For Java LDAP injection vulnerability

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-qcj7-g2j5-g7r3 — In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verification

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-r97x-3g8f-gx3m — The Bouncy Castle JCE Provider carry a propagation bug

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-r9ch-m4fh-fc7q — Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-rrvx-pwf8-p59p — In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-v435-xc8x-wvr9 — Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-w285-wf9q-5w69 — In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB mode

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-wjxj-5m7g-mg7q — Bouncy Castle Denial of Service (DoS)

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-wrwf-pmmj-w989 — Observable Discrepancy in BouncyCastle

    component: bouncycastle

  • Historical CVE on SDK (build version not detected): Bouncy CastleSDK vulnerability · info

    GHSA-xqj7-j8j5-f2xr — Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator

    component: bouncycastle

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.activities.MainCredentialActivity (activity)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.activities.FileDatabaseSelectActivity (activity)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.credentialprovider.activity.EntrySelectionLauncherActivity (activity)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.settings.MagikeyboardSettingsActivity (activity)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.credentialprovider.passkey.PasskeyProviderService (service)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.credentialprovider.autofill.KeeAutofillService (service)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.credentialprovider.magikeyboard.MagikeyboardService (service)

  • Exported Android componentExported component · info

    androidx.profileinstaller.ProfileInstallReceiver (receiver)

  • Exported Android componentExported component · info

    com.kunzisoft.keepass.receivers.DexModeReceiver (receiver)

Want PR-level context for this app?

Connect the GitHub repo for this app to upgrade to L3. You'll get per-PR Check Runs, source-aware risk factors, and root-cause attribution against this exact bundle.

Compare tiers