NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-39925
Summary

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the organization key. Additionally, the application fails to adequately protect some encrypted data stored on the server. Consequently, an authenticated user could gain unauthorized access to encrypted data of any organization, even if the user is not a member of the targeted organization. However, the user would need to know the corresponding organizationId. Hence, if a user (whose access to an organization has been revoked) already possesses the organization key, that user could use the key to decrypt the leaked data.

Publication Date Sept. 14, 2024, 3:15 a.m.
Registration Date Sept. 14, 2024, noon
Last Update Nov. 12, 2024, 6:15 a.m.
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
Daniel Garcia の Vaultwarden における情報漏えいに関する脆弱性
Title Daniel Garcia の Vaultwarden における情報漏えいに関する脆弱性
Summary

Daniel Garcia の Vaultwarden には、情報漏えいに関する脆弱性が存在します。

Possible impacts 情報を取得される可能性があります。
Solution

参考情報を参照して適切な対策を実施してください。

Publication Date Sept. 13, 2024, midnight
Registration Date July 11, 2025, 12:24 p.m.
Last Update July 11, 2025, 12:24 p.m.
Affected System
Daniel Garcia
Vaultwarden 1.30.3
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
その他
Change Log
No Changed Details Date of change
1 [2025年07月11日]   掲載 July 11, 2025, 12:12 p.m.