VDB
Sign up
HIGH

GHSA-x7m9-mv49-fv73

Vaultwarden vulnerable to user impersonation

Details

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/vaultwarden
Introduced in: 0Fixed in: 1.32.5

Upgrade vaultwarden to 1.32.5 or newer (ecosystem crates.io).

References