Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Vaultwarden 1.37.4 schließt mehrere Sicherheitslücken
Vaultwarden 1.37.4 schließt mehrere Sicherheitslücken, darunter eine mit hohem Schweregrad beim Entzug von Organisationsmitgliedern sowie weitere in Zwei-Faktor-Authentifizierung, Einladungen, Anhängen, Ereignisprotokollen, Cipher-Freigabe und Organisations-API-Key, und sollte schnellstmöglich installiert werden.
Security Fixes
This release contains security fixes for the following advisories. We strongly advise updating as soon as possible.
- Organization member revocation [GHSA-69q9-v8p6-xvx3] (High, 8.1)
- Two-factor authentication [GHSA-7jg8-8m5x-6j9r] (Medium, 6.8)
- Organization invitations [GHSA-v576-3wvq-xh3c] (Medium, 6.8)
- Attachments [GHSA-q5x6-grh5-fqgc] (Medium, 6.5)
- Organization event logs [GHSA-64mc-4p6f-r7x9] (Medium, 4.3)
- Cipher sharing [GHSA-7ccc-c43j-4p36] (Medium, 4.3)
- Organization API key [GHSA-qwx4-wcv4-mpcv] (Low, 3.8)
- Additional dependency updates and minor security enhancements
These are private for now, pending CVE assignment and publishing at a later date.
[!NOTE] …