Skip to content

[GHSA-36qw-697c-h8mq] A vulnerability was found in Bitwarden up to 2.25.1. It... #5737

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

bwbug
Copy link

@bwbug bwbug commented Jun 20, 2025

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • Severity
  • Summary

Comments
Refer to discussion here, especially the links in this comment. The evidence that the submitter's Proof-of-Concept used Vaultwarden (not Bitwarden) can be found in the footer of the screenshots here.

Given that the submitter consistently misidentifies Vaultwarden (which is not a Bitwarden product) as "Bitwarden", their claim about having contacted the "vendor" is suspect. The "vendor" of Vaultwarden is Dani Garcia, so it is no surprise that if the submitter contacted Bitwarden Inc. or 8bit Solutions LLC about a vulnerability in a competitor's product, there would be no response.

I am unfamiliar with the various Exploitability and Impact metrics, so I have not proposed any changes in the metrics section. I changed the "severity" from "Moderate" to "Low", given that this vulnerability has only been proven in a product that has been deprecated for over 3 years.

@github-actions github-actions bot changed the base branch from main to bwbug/advisory-improvement-5737 June 20, 2025 00:08
@shelbyc
Copy link
Contributor

shelbyc commented Jun 20, 2025

Hi @bwbug, I can't make any changes to this advisory because neither Vaulwarden nor Bitwarden are products in one of the GitHub Advisory Database's supported ecosystems. If you wish to have the CVE record corrected, I would recommend using this guide to find the contact information for VulDB, the CVE Numbering Authority for the CVE, and ask them to make a correction. Best wishes for updating the CVE record and have a good weekend!

@shelbyc shelbyc closed this Jun 20, 2025
@github-actions github-actions bot deleted the bwbug-GHSA-36qw-697c-h8mq branch June 20, 2025 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants