CVE-2018-25081: Infoleak
DISPUTED Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME element on the icloud.com website) and that "Auto-fill on page load" is not enabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25081?
The severity of CVE-2018-25081 is currently disputed due to varying interpretations of its impact on password security.
How do I fix CVE-2018-25081?
To mitigate CVE-2018-25081, upgrade to a version of Bitwarden later than 2023.2.1 if possible.
What is the main issue in CVE-2018-25081?
CVE-2018-25081 involves password auto-fill functionality being available within cross-domain IFRAME elements, which could lead to security risks.
Is Bitwarden affected by CVE-2018-25081?
Yes, Bitwarden versions up to and including 2023.2.1 are affected by CVE-2018-25081.
What should users be aware of regarding CVE-2018-25081?
Users should be aware that CVE-2018-25081 may allow unintended access to passwords through IFRAMEs if they are using an affected version of Bitwarden.