icon

We found results for “

WS-2024-0012

Good to know:

icon

Date: June 4, 2024

In vaultwarden before 1.33.0, an Attacker can create malicious html page that sends http request to the vaultwarden admin page for change. HTTP server doesn't verify Content-Type header. This requires the DISABLE_ADMIN_TOKEN option to be enabled, as the authentication cookie will not be sent across site boundaries.

Language: C

Severity Score

Weakness Type (CWE)

Out-of-bounds Read

CWE-125

Top Fix

icon

Upgrade Version

Upgrade to version vaultwarden - no_fix

Learn More

CVSS v3

Base Score:
Attack Vector (AV):
Attack Complexity (AC):
Privileges Required (PR):
User Interaction (UI):
Scope (S):
Confidentiality (C):
Integrity (I):
Availability (A):

Do you need more information?

Contact Us