vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of other organization (by default you can create your own organization) in order to attack. This vulnerability is fixed in 1.33.0.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Jan 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of other organization (by default you can create your own organization) in order to attack. This vulnerability is fixed in 1.33.0. | |
Title | vaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-27T17:49:57.796Z
Updated: 2025-02-12T20:41:36.070Z
Reserved: 2025-01-20T15:18:26.990Z
Link: CVE-2025-24365

No data.

Status : Received
Published: 2025-01-27T18:15:41.847
Modified: 2025-01-27T18:15:41.847
Link: CVE-2025-24365

No data.