HIGH
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element
Published Mar 8, 2023
7.5
HIGHCVSS 3.1
EPSS 1.03%
Description
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME element on the icloud.com website) and that "Auto-fill on page load" is not enabled by default.
Affected products
No data.
-
- Version 0StatusaffectedConstraints<=2023.2.1
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assessment%20Report.pdf Technical DescriptionVendor Advisory
- https://flashpoint.io/blog/bitwarden-password-pilfering/ ExploitThird Party Advisory
- https://github.com/bitwarden/clients/releases Release Notes
- https://news.ycombinator.com/item?id=35075861 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assessment%20Report.pdf | Technical DescriptionVendor Advisory | |
| https://flashpoint.io/blog/bitwarden-password-pilfering/ | ExploitThird Party Advisory | |
| https://github.com/bitwarden/clients/releases | Release Notes | |
| https://news.ycombinator.com/item?id=35075861 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 8, 2023
Updated Aug 19, 2024
Reserved Mar 8, 2023
Link CVE-2018-25081
CISA Vulnrichment
Updated Aug 19, 2024