Vaultwarden 1.35.5

1.35.5
Added 5
  • Add feature flag for Safari account switching
  • Add Webauthn related origins flag to known flags
  • Add 30-second cache to SSO exchange_refresh_token
  • Add cxp-import-mobile and cxp-export-mobile feature flags on mobile
  • Handle SIGTERM and SIGQUIT shutdown signals
Changed 3
  • Support new desktop origin on CORS
  • Two Factor Remember Tokens are now valid for maximum 30 days
  • Change SQLite backup to use VACUUM INTO query
Fixed 9
  • Apply policies only to confirmed members
  • Add ForcePasswordReset to API key login
  • Fix API key login
  • Fix email header base64 padding
  • Fix empty string FolderId
  • Fix Send icons
Security 3
  • Fix unconfirmed owner ability to purge entire organization vault
  • Fix cross-org group binding that enabled unauthorized read and write access into another organization
  • Invalidate refresh tokens on security stamp rotation
Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Notes
  • The admin templates have changed, please update them if you override these via templates.
  • Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.
What's Changed
New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.4...1.35.5

View original

Upgraded? How did it go?

Discussion