PT-2024-36796 · Unknown+1 · Vaultwarden+1
Blackdex
+1
·
Published
2024-12-20
·
Updated
2025-08-19
·
CVE-2024-56335
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
vaultwarden versions prior to 1.32.7
Description
The issue allows an attacker to update or delete groups from an organization under certain conditions: the attacker has a user account in the server, the attacker's account has admin or owner permissions in an unrelated organization, and the attacker knows the target organization's UUID and the target group's UUID. This can lead to denial of service or privilege escalation. The attack is only applicable for servers with the
ORG GROUPS ENABLED setting enabled, which is disabled by default.Recommendations
For versions prior to 1.32.7, update to version 1.32.7 as soon as possible.
If updating to 1.32.7 is not possible, consider disabling the
ORG GROUPS ENABLED setting to disable groups functionality on the server.
Alternatively, disabling SIGNUPS ALLOWED can prevent an attacker from creating new accounts on the server.Exploit
Fix
DoS
LPE
Improper Access Control
Improper Authentication
Improper Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Vaultwarden