CVE-2023-38840
MEDIUMCVSS 5.5/10EPSS 0.56%
Last modified
CVE-2023-38840 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bitwarden | Bitwarden | <= 2023.7.0 |
References
- https://github.com/bitwarden/clients/pull/5813Patch, Third Party Advisory
- https://github.com/bitwarden/desktop/issues/476Issue Tracking, Third Party Advisory
- https://github.com/markuta/bw-dumpThird Party Advisory
- https://redmaple.tech/blogs/2023/extract-bitwarden-vault-passwords/Third Party Advisory
- https://github.com/bitwarden/clients/pull/5813Patch, Third Party Advisory
- https://github.com/bitwarden/desktop/issues/476Issue Tracking, Third Party Advisory
- https://github.com/markuta/bw-dumpThird Party Advisory
- https://redmaple.tech/blogs/2023/extract-bitwarden-vault-passwords/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-38840?
Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.
How severe is CVE-2023-38840?
CVE-2023-38840 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.56% probability of exploitation in the next 30 days.
How do I fix CVE-2023-38840?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-38830An information leak in PHPJabbers Yacht Listing Script v1.0 …7.5
- CVE-2023-38831RARLAB WinRAR before 6.23 allows attackers to execute arbitr…7.8
- CVE-2023-38836File Upload vulnerability in BoidCMS v.2.0.0 allows a remote…8.8
- CVE-2023-38838SQL injection vulnerability in Kidus Minimati v.1.0.0 allows…7.5
- CVE-2023-38839SQL injection vulnerability in Kidus Minimati v.1.0.0 allows…7.5
- CVE-2023-3884A vulnerability has been found in Campcodes Beauty Salon Man…6.1
- CVE-2023-38843An issue in Atlos v.1.0 allows an authenticated attacker to …8
- CVE-2023-38844SQL injection vulnerability in PMB v.7.4.7 and earlier allow…7.5
- CVE-2023-38845An issue in Anglaise Company Anglaise.Company v.13.6.1 allow…7.5
- CVE-2023-38846An issue in Marbre Lapin Line v.13.6.1 allows a remote attac…7.5
- CVE-2023-38847An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote at…7.5
- CVE-2023-38848An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remot…7.5
Are you affected by CVE-2023-38840?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
