Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: vaultwarden

Found 4 matching suggestions

updated 4 days, 5 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package vaultwarden-webvault
  • @LeSuisse accepted
  • @LeSuisse removed
    2 maintainers
    • @dotlambda
    • @SuperSandro2000
  • @LeSuisse published on GitHub
Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.

Affected products

vaultwarden
  • ==< 1.35.4

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Upstream advisory: https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-r32r-j5jq-3w4m
updated 4 days, 5 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package vaultwarden-webvault
  • @LeSuisse accepted
  • @LeSuisse removed
    2 maintainers
    • @dotlambda
    • @SuperSandro2000
  • @LeSuisse published on GitHub
Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

Affected products

vaultwarden
  • ==< 1.35.4

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Upstream advisory: https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-w9f8-m526-h7fh
updated 4 days, 5 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package vaultwarden-webvault
  • @LeSuisse accepted
  • @LeSuisse removed
    2 maintainers
    • @dotlambda
    • @SuperSandro2000
  • @LeSuisse published on GitHub
Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4.

Affected products

vaultwarden
  • ==< 1.35.4

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Upstream advisory: https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-h4hq-rgvh-wh27
updated 4 days, 5 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package vaultwarden-webvault
  • @LeSuisse accepted
  • @LeSuisse removed
    2 maintainers
    • @dotlambda
    • @SuperSandro2000
  • @LeSuisse published on GitHub
Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the user’s API key or deleting the user’s vault and organisations the user is an admin/owner of . This issue has been patched in version 1.35.0.

Affected products

vaultwarden
  • ==< 1.35.0

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Upstream advisory: https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-v6pg-v89r-w8wr