CVE-2018-25081: Infoleak

Published Mar 8, 2023
·
Updated

DISPUTED Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME element on the icloud.com website) and that "Auto-fill on page load" is not enabled by default.

Affected Software

1 affected component
Bitwarden Bitwarden<=2023.2.1

Event History

Mar 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 9, 2023
Disputed
12:15 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-25081?

The severity of CVE-2018-25081 is currently disputed due to varying interpretations of its impact on password security.

2

How do I fix CVE-2018-25081?

To mitigate CVE-2018-25081, upgrade to a version of Bitwarden later than 2023.2.1 if possible.

3

What is the main issue in CVE-2018-25081?

CVE-2018-25081 involves password auto-fill functionality being available within cross-domain IFRAME elements, which could lead to security risks.

4

Is Bitwarden affected by CVE-2018-25081?

Yes, Bitwarden versions up to and including 2023.2.1 are affected by CVE-2018-25081.

5

What should users be aware of regarding CVE-2018-25081?

Users should be aware that CVE-2018-25081 may allow unintended access to passwords through IFRAMEs if they are using an affected version of Bitwarden.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203