LOW
GHSA-vprm-27pv-jp3w
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Details
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/vaultwarden
Introduced in:
0Fixed in: 1.32.5Upgrade vaultwarden to 1.32.5 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-55226[ADVISORY]
- https://github.com/dani-garcia/vaultwarden[PACKAGE]
- https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4[WEB]
- https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5[WEB]
- https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5[WEB]