CVE-2024-55225: Critical severity rust/vaultwarden vulnerability
Published Jan 9, 2025
·Updated
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
Affected Software
2 affected componentsFixes available
rust/vaultwarden<1.32.5
1.32.5
Dani-garcia Vaultwarden<1.32.5
Event History
Jan 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-55225?
CVE-2024-55225 is a critical vulnerability that allows attackers to impersonate users, including administrators, due to an authentication bypass.
2
How do I fix CVE-2024-55225?
To fix CVE-2024-55225, upgrade Vaultwarden to version 1.32.5 or later immediately.
3
What systems are affected by CVE-2024-55225?
CVE-2024-55225 affects all versions of Vaultwarden prior to 1.32.5.
4
What type of attack is enabled by CVE-2024-55225?
CVE-2024-55225 enables impersonation attacks where an attacker can assume the identity of any user, including administrators.
5
Is there a patch available for CVE-2024-55225?
Yes, a patch is available in Vaultwarden version 1.32.5 which resolves CVE-2024-55225.