CVE-2020-15879: SSRF
Published Jul 21, 2020
·Updated
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
Affected Software
1 affected component
Bitwarden server=1.35.1
Event History
Jul 21, 2020
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15879?
CVE-2020-15879 has a medium severity level due to its potential for server-side request forgery (SSRF) attacks.
2
How do I fix CVE-2020-15879?
To fix CVE-2020-15879, upgrade the Bitwarden Server to version 1.35.2 or later where the vulnerability is addressed.
3
What does CVE-2020-15879 affect?
CVE-2020-15879 affects Bitwarden Server version 1.35.1 specifically.
4
What is the main issue described in CVE-2020-15879?
The main issue in CVE-2020-15879 is that the application allows SSRF by not properly handling certain IPv4 and IPv6 addresses.
5
Are earlier versions of Bitwarden Server affected by CVE-2020-15879?
Yes, earlier versions prior to 1.35.2 are affected by CVE-2020-15879 and should be updated.