CVE-2024-55224: XSS
Published Jan 9, 2025
·Updated
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
Affected Software
2 affected componentsFixes available
rust/vaultwarden<1.32.5
1.32.5
Dani-garcia Vaultwarden<1.32.5
Event History
Jan 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-55224?
CVE-2024-55224 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-55224?
To fix CVE-2024-55224, upgrade Vaultwarden to version 1.32.5 or later.
3
What software is affected by CVE-2024-55224?
CVE-2024-55224 affects Vaultwarden versions prior to 1.32.5.
4
Can CVE-2024-55224 lead to data breaches?
Yes, CVE-2024-55224 can potentially lead to data breaches if exploited by an attacker.
5
Is CVE-2024-55224 related to email security?
Yes, CVE-2024-55224 specifically involves an HTML injection vulnerability in the username field of an email message.