PT-2024-28737 · Unknown · Vaultwarden

Mirko Richter

+1

·

Published

2024-09-13

·

Updated

2025-07-10

·

CVE-2024-39925

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vaultwarden (formerly Bitwarden RS) version 1.30.3
Description An issue was discovered in Vaultwarden, which lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs, and the departing member retains a copy of the organization key. The application also fails to adequately protect some encrypted data stored on the server, allowing an authenticated user to gain unauthorized access to encrypted data of any organization, even if the user is not a member of the targeted organization, provided they know the corresponding organizationId.
Recommendations For Vaultwarden version 1.30.3, consider implementing a proper offboarding process to rotate the shared organization key when a member departs, and ensure that access to encrypted data is properly revoked for departing members. As a temporary workaround, restrict access to the encrypted data stored on the server to minimize the risk of exploitation. Additionally, consider disabling the feature that allows authenticated users to access encrypted data of other organizations until a proper fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-39925

Affected Products

Vaultwarden