CVE-2024-56335
Last modified
CVE-2024-56335 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2. The attacker's account has admin or owner permissions in an unrelated organization. 3. The attacker knows the target organization's UUID and the target group's UUID. Note that this vulnerability is related to group functionality and as such is only applicable for servers who have enabled the `ORG_GROUPS_ENABLED` setting, which is disabled by default. This attack can lead to different situations: 1. Denial of service, the attacker can limit users from accessing the organization's data by removing their membership from the group. 2. Privilege escalation, if the attacker is part of the victim organization, they can escalate their own privileges by joining a group they wouldn't normally have access to. For attackers that aren't part of the organization, this shouldn't lead to any possible plain-text data exfiltration as all the data is encrypted client side. This vulnerability is patched in Vaultwarden `1.32.7`, and users are recommended to update as soon as possible. If it's not possible to update to `1.32.7`, some possible workarounds are: 1. Disabling `ORG_GROUPS_ENABLED`, which would disable groups functionality on the server. 2. Disabling `SIGNUPS_ALLOWED`, which would not allow an attacker to create new accounts on the server.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dani-Garcia | Vaultwarden | < 1.32.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-56335?
How severe is CVE-2024-56335?
How do I fix CVE-2024-56335?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5633Longse model LBH30FE200W cameras, as well as products based …7.5
- CVE-2024-56330Stardust is a platform for streaming isolated desktop contai…9.3
- CVE-2024-56331Uptime Kuma is an open source, self-hosted monitoring tool. …6.8
- CVE-2024-56332Next.js is a React framework for building full-stack web app…5.3
- CVE-2024-56333Onyxia is a web app that aims at being the glue between mult…9.4
- CVE-2024-56334systeminformation is a System and OS information library for…7.8
- CVE-2024-56336A vulnerability has been identified in SINAMICS S200 (All ve…9.8
- CVE-2024-56337Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabil…9.8
- CVE-2024-56338IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through…4.8
- CVE-2024-56339IBM WebSphere Application Server 9.0 and WebSphere Applicati…7.5
- CVE-2024-5634Longse model LBH30FE200W cameras, as well as products based …8.6
- CVE-2024-56340IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable…6.5
Are you affected by CVE-2024-56335?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
