LOW
GHSA-g5x8-v2ch-gj2g
Vaultwarden HTML injection vulnerability
Details
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/vaultwarden
Introduced in:
0Fixed in: 1.32.5Upgrade vaultwarden to 1.32.5 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-55224[ADVISORY]
- https://github.com/dani-garcia/vaultwarden[PACKAGE]
- https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4[WEB]
- https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5[WEB]
- https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5[WEB]