CVE-2023-38840: Medium severity bitwarden vulnerability
Published Aug 15, 2023
·Updated
Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.
Affected Software
1 affected component
Bitwarden Bitwarden<=2023.7.0
Remediation
Patch Available
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38840?
CVE-2023-38840 is considered a high severity vulnerability due to the risk of sensitive information exposure with local access.
2
How do I fix CVE-2023-38840?
To fix CVE-2023-38840, upgrade to Bitwarden Desktop version 2023.8.0 or later.
3
What type of access is needed to exploit CVE-2023-38840?
CVE-2023-38840 requires local access to the system to exploit the vulnerability.
4
What information can be exposed through CVE-2023-38840?
CVE-2023-38840 may expose sensitive information stored within the Bitwarden application, such as passwords and secure notes.
5
Which versions of Bitwarden are affected by CVE-2023-38840?
CVE-2023-38840 affects Bitwarden Desktop versions 2023.7.0 and below.