CVE-2023-27974: High severity bitwarden vulnerability
DISPUTED Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's position is that "Auto-fill on page load" is not enabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27974?
CVE-2023-27974 has been categorized as disputed and does not have a defined severity level from the vendor.
How do I fix CVE-2023-27974?
To mitigate CVE-2023-27974, ensure that auto-fill on page load features are disabled in your Bitwarden settings.
What software is affected by CVE-2023-27974?
CVE-2023-27974 affects Bitwarden version 2023.2.1 and earlier versions on browser platforms.
What type of vulnerability is CVE-2023-27974?
CVE-2023-27974 pertains to a potential issue with password auto-fill functionality based on domain matching.
Can exploited CVE-2023-27974 lead to data leakage?
Yes, CVE-2023-27974 could potentially allow unauthorized access to saved passwords if auto-fill is inadvertently triggered.