Zum Inhalt springen

Daniel García Release Notes

30 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.33.1

Version 1.33.1 behebt mehrere kleinere Probleme, darunter Icons in Desktop-Clients, Einladungen, die Duo-Konfiguration, Manager-Rechte und Sync-Probleme mobiler Clients.

General mention

This release has some minor issues fixed like:

  • Icon's not working on the Desktop clients
  • Invites not always working
  • DUO settings not able to configure
  • Manager rights
  • Mobile client sync issues fixed

What's Changed

New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.33.0...1.33.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.33.0 mit Sicherheitskorrekturen

Version 1.33.0 behebt drei Sicherheitslücken (u. a. betreffend fehlenden ADMIN_TOKEN, Sendmail-Missbrauch im Admin-Backend und Organisationen), aktualisiert den Web-Vault auf v2025.1.1 und ergänzt teilweise Unterstützung der Rolle *manage* für Collections.

Security Fixes

This release contains security fixes for the following advisories. And we strongly advice to update as soon as possible.

  • GHSA-f7r5-w49x-gxm3 This vulnerability is only possible if you do not have an ADMIN_TOKEN configured and open links or pages you should not trust anyway. Ensure you have an ADMIN_TOKEN configured to keep your admin environment save.
  • GHSA-h6cc-rc6q-23j4 This vulnerability is only possible if someone was able to gain access to your Vaultwarden Admin Backend. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell command. It then also needed to craft a special favicon image which would have the commands embedded to run during for example sending a test email.
  • GHSA-j4h8-vch3-f797 This vulnerability affects all users who have multiple Organizations and users which are able to create a new organization or have admin or owner rights on at least one organization. The attacker does need to know the Organization UUID of the Organization it want's to attack or compromise though.

Notable changes

  • Updated web-vault to v2025.1.1
  • Added partial manage role support for collections …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.7 mit Sicherheitskorrektur

Version 1.32.7 behebt eine Sicherheitslücke, die Installationen mit aktivierter Einstellung ORG_GROUPS_ENABLED betrifft, und erlaubt zusätzlich das Hinzufügen von connect-src-Einträgen.

Security Fixes

This release contains a security fix for the following CVE https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-g65h-982x-4m5m.

This vulnerability affects any installations that have the ORG_GROUPS_ENABLED setting enabled, and we urge anyone doing so to update as soon as possible.

What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.32.6...1.32.7

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.6

Version 1.32.6 behebt Probleme mit Push-Benachrichtigungen, dem Bearbeiten von Mitgliedern mit Access-All-Rechten und der Synchronisierung nativer Clients, aktualisiert Alpine auf 3.21 und bringt Korrekturen im Admin-Backend.

What's Changed

New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.32.5...1.32.6

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.5 mit SSH-Key-Unterstützung

Version 1.32.5 behebt weitere gemeldete Sicherheitsprobleme, fügt Unterstützung für die SSH-Key-Speicherung hinzu (nur mit Bitwarden Desktop ab v2024.12.0 und per Feature-Flag in EXPERIMENTAL_CLIENT_FEATURE_FLAGS) und ergänzt dynamisches CSS sowie Auth-Request-Korrekturen.

Security Fixes

This release further fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.

Notable changes

  • Added SSH-Key storage support. Currently only usable with Bitwarden Desktop v2024.12.0 and newer. You need to enable this feature by adding ssh-key-vault-item,ssh-agent to the EXPERIMENTAL_CLIENT_FEATURE_FLAGS config option. See .env.template

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.4 mit Sicherheitskorrekturen

Version 1.32.4 behebt von einem externen Auditor gemeldete Sicherheitsprobleme, verbessert die Kompatibilität mit nativen Mobile-Apps durch kürzere Datumsformate und ändert das E-Mail-Template für Notfallzugriff-Einladungen.

Security Fixes

This release has fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.

Notable changes

  • Added more compatibility fixes for the native mobile apps, datetimes are now formatted without too many decimals.
  • Email Template changes to the send emergency access invite. If you have modified this template, make sure to update it with the new changes.

What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.32.3...1.32.4

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.3

Version 1.32.3 korrigiert die HTML-Kodierung der URL in Organisations-Einladungen, behebt SMTP-Probleme mit Anbietern wie QQ, repariert die Collection-Verwaltung im Password Manager und fügt das Feature-Flag extension-refresh hinzu.

Notable changes

  • Email template for org invites was updated again. The URL got HTML Encoded which resulted in a sometimes non-working URL (#5100)
  • Fixed SMTP issues with some providers which send erroneous response to QUIT messages (Like QQ) (Thanks to @paolobarbolini)
  • Fixed a long standing collection management issue where collections were not able to be managed via the Password Manager overview

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.2

Version 1.32.2 behebt die Collection-Verwaltung für Manager sowie Probleme beim Kompilieren für Windows und bei --version ohne Konfiguration.

Notable changes

  • Fixed collection management for managers

What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.32.1...1.32.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.1

Version 1.32.1 behebt Sync und Login mit nativen Mobile-Clients, fügt eine CLI-Option zum Backup der SQLite-Datenbank hinzu und ändert E-Mail-Templates für Einladungen, unvollständige 2FA-Logins und neue Logins.

Notable changes

  • Fixed syncing/login with native mobile clients
  • Added CLI option to backup SQLite database
  • Email Template changes regarding invites, 2FA Incomplete logins, and new logins

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Vaultwarden von Daniel García

Vaultwarden 1.32.0 behebt mehrere CVEs

Vaultwarden 1.32.0 behebt die Sicherheitslücken CVE-2024-39924, CVE-2024-39925 und CVE-2024-39926, aktualisiert das web-vault auf v2024.6.2, behebt Probleme bei der Passwort-Reset-Registrierung und enthält weitere Fehlerkorrekturen wie den E-Mail-2FA-Login in der nativen App.

Security Fixes

This release has several CVE Reports fixed and we recommend everybody to update to the latest version as soon as possible.

Other changes

  • Updated web-vault to v2024.6.2
  • Fixed issues with password reset enrollment by rolling back a web-vault commit

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden