mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-02-05 00:29:40 +03:00
There are loopholes in the Vaultwarden versin 1.28.1 #1629
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @hzpurewater on GitHub (Jul 5, 2023).
Using vulnerability scanning tools to scan Vaultwarden version 1.28.1, many bugs were found。I hope it can be resolved as soon as possible。

The detailed vulnerabilities are as follows:
@BlackDex commented on GitHub (Jul 5, 2023):
I'm not seeing bugs linked to Vaultwarden.
What did you used to scan? And what did you scan?
@RuneNyhuus commented on GitHub (Jul 5, 2023):
Have this issue been fixed?
https://labs.hakaioffsec.com/nginx-alias-traversal/
I think i just lost my vault to an hacker, and they prop. used this method?
@BlackDex commented on GitHub (Jul 5, 2023):
Vaultwarden doesn't use nginx it self, so thats not vulnerable via that way. Also, Vaultwarden it self is not vulnerable to traversal.
I also do not see how a hacker would have stole your vault. If, then they would have had your credentials.