VYPR

Vaultwarden

by Vaultwarden

Source repositories

CVEs (3)

  • CVE-2024-39924HigSep 13, 2024
    risk 0.51cvss 8.8epss 0.13

    An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency…

  • CVE-2024-39925MedSep 13, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be…

  • CVE-2024-39926MedSep 13, 2024
    risk 0.28cvss 5.4epss 0.00

    An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious…