CVE-2024-55226: XSS
Published Jan 9, 2025
·Updated
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
Affected Software
2 affected componentsFixes available
rust/vaultwarden<1.32.5
1.32.5
Dani-garcia Vaultwarden=1.32.5
Remediation
Event History
Jan 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyAffected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-55226?
CVE-2024-55226 is classified as a medium severity vulnerability due to its ability to execute authenticated reflected cross-site scripting attacks.
2
How do I fix CVE-2024-55226?
To fix CVE-2024-55226, upgrade Vaultwarden to the latest version beyond 1.32.5.
3
What component is affected by CVE-2024-55226?
CVE-2024-55226 impacts the /api/core/mod.rs component of Vaultwarden.
4
Who is affected by CVE-2024-55226?
All users running Vaultwarden version 1.32.5 are affected by CVE-2024-55226.
5
What type of vulnerability is CVE-2024-55226?
CVE-2024-55226 is an authenticated reflected cross-site scripting (XSS) vulnerability.