There are loopholes in the Vaultwarden versin 1.28.1 #1629

Closed
opened 2026-02-05 01:22:38 +03:00 by OVERLORD · 3 comments
Owner

Originally created by @hzpurewater on GitHub (Jul 5, 2023).

Using vulnerability scanning tools to scan Vaultwarden version 1.28.1, many bugs were found。I hope it can be resolved as soon as possible。
The detailed vulnerabilities are as follows:
22

Originally created by @hzpurewater on GitHub (Jul 5, 2023). Using vulnerability scanning tools to scan Vaultwarden version 1.28.1, many bugs were found。I hope it can be resolved as soon as possible。 The detailed vulnerabilities are as follows: ![22](https://github.com/dani-garcia/vaultwarden/assets/40298933/dec1fabf-aee2-4bf2-a0d9-fcb48c4fc678)
Author
Owner

@BlackDex commented on GitHub (Jul 5, 2023):

I'm not seeing bugs linked to Vaultwarden.
What did you used to scan? And what did you scan?

@BlackDex commented on GitHub (Jul 5, 2023): I'm not seeing bugs linked to Vaultwarden. What did you used to scan? And what did you scan?
Author
Owner

@RuneNyhuus commented on GitHub (Jul 5, 2023):

Have this issue been fixed?
https://labs.hakaioffsec.com/nginx-alias-traversal/

I think i just lost my vault to an hacker, and they prop. used this method?

@RuneNyhuus commented on GitHub (Jul 5, 2023): Have this issue been fixed? https://labs.hakaioffsec.com/nginx-alias-traversal/ I think i just lost my vault to an hacker, and they prop. used this method?
Author
Owner

@BlackDex commented on GitHub (Jul 5, 2023):

Vaultwarden doesn't use nginx it self, so thats not vulnerable via that way. Also, Vaultwarden it self is not vulnerable to traversal.

I also do not see how a hacker would have stole your vault. If, then they would have had your credentials.

@BlackDex commented on GitHub (Jul 5, 2023): Vaultwarden doesn't use nginx it self, so thats not vulnerable via that way. Also, Vaultwarden it self is not vulnerable to traversal. I also do not see how a hacker would have stole your vault. If, then they would have had your credentials.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/vaultwarden#1629