CVE-2019-19766: High severity bitwarden vulnerability
Published Dec 12, 2019
·Updated
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
Affected Software
1 affected component
Bitwarden server<=1.32.0
Event History
Dec 12, 2019
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19766?
CVE-2019-19766 is classified as a medium severity vulnerability due to its potential impact on password security.
2
How do I fix CVE-2019-19766?
To mitigate CVE-2019-19766, upgrade the Bitwarden server to a version higher than 1.32.0.
3
What kind of vulnerability is CVE-2019-19766?
CVE-2019-19766 is a security issue related to the use of a potentially unwanted key derivation function (KDF) in the Bitwarden server.
4
Is my data at risk with CVE-2019-19766?
Yes, if you are using Bitwarden server version 1.32.0 or lower, your data may be at risk due to inadequate password hashing.
5
When was CVE-2019-19766 published?
CVE-2019-19766 was published in December 2019.