Vaultwarden 1.35.3

1.35.3
Changed 2
  • Improve tooltips in diagnostics page
  • Update crates, web-vault, and JavaScript dependencies
Fixed 7
  • Fix User API Key login
  • Use email instead of empty name for WebAuthn
  • Hide password hints via CSS
  • Fix email as 2FA with auth requests
  • Empty AccountKeys when no private key
  • Fix error message for purging auth requests
  • Fix org-details issue
Security 1
  • Fix vulnerability allowing authenticated attackers in an organization to access items from collections they do not belong to (GHSA-h265-g7rm-h337)
Security Fixes

This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.

  • GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment) This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.
What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.2...1.35.3

View original

Upgraded? How did it go?

Discussion