CVE-2025-24365

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 27, 2025
CWE ID 284

Summary

CVE-2025-24365 affects the unofficial Bitwarden compatible server, vaultwarden. This vulnerability, which was formerly known as bitwarden_rs, enables an attacker to obtain owner rights of another organization. To exploit this issue, the attacker needs to know the ID of the victim organization and be the owner or admin of another organization. This vulnerability has been addressed in version 1.33.0 of vaultwarden.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share