Vaultwarden 1.35.4

1.35.4
Changed 2
  • Hide remember 2FA token
  • Miscellaneous organization fixes
Fixed 1
  • Fix invite links in send invitations
Security 3
  • Fix vulnerability allowing an attacker to access a cipher from a different user if they know its internal UUID
  • Fix vulnerability allowing an attacker with manager-level access within an organization to modify collections they can access without management permissions
  • Fix vulnerability allowing an attacker with manager-level access within an organization to modify collections they are not assigned
Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

  • GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
  • GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
  • GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.

These are private for now, pending CVE assignment.

What's Changed
New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.3...1.35.4

View original

Upgraded? How did it go?

Discussion