FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Vaultwarden -- Admin organization permissions

Affected packages
vaultwarden < 1.32.7

Details

VuXML ID 0a8dbc7f-bedc-11ef-b5a1-000ec6d40964
Discovery 2024-12-20
Entry 2024-12-20

The Vaultwarden project reports:

Admins from any organization were able to modify or delete groups in any other organization if they know the group's uuid.

References

URL https://github.com/dani-garcia/vaultwarden/pull/5291