Originally created by @hzpurewater on GitHub (Jul 5, 2023).
Using vulnerability scanning tools to scan Vaultwarden version 1.28.1, many bugs were found。I hope it can be resolved as soon as possible。
The detailed vulnerabilities are as follows:
Originally created by @hzpurewater on GitHub (Jul 5, 2023).
Using vulnerability scanning tools to scan Vaultwarden version 1.28.1, many bugs were found。I hope it can be resolved as soon as possible。
The detailed vulnerabilities are as follows:

I think i just lost my vault to an hacker, and they prop. used this method?
@RuneNyhuus commented on GitHub (Jul 5, 2023):
Have this issue been fixed?
https://labs.hakaioffsec.com/nginx-alias-traversal/
I think i just lost my vault to an hacker, and they prop. used this method?
Vaultwarden doesn't use nginx it self, so thats not vulnerable via that way. Also, Vaultwarden it self is not vulnerable to traversal.
I also do not see how a hacker would have stole your vault. If, then they would have had your credentials.
@BlackDex commented on GitHub (Jul 5, 2023):
Vaultwarden doesn't use nginx it self, so thats not vulnerable via that way. Also, Vaultwarden it self is not vulnerable to traversal.
I also do not see how a hacker would have stole your vault. If, then they would have had your credentials.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @hzpurewater on GitHub (Jul 5, 2023).
Using vulnerability scanning tools to scan Vaultwarden version 1.28.1, many bugs were found。I hope it can be resolved as soon as possible。

The detailed vulnerabilities are as follows:
@BlackDex commented on GitHub (Jul 5, 2023):
I'm not seeing bugs linked to Vaultwarden.
What did you used to scan? And what did you scan?
@RuneNyhuus commented on GitHub (Jul 5, 2023):
Have this issue been fixed?
https://labs.hakaioffsec.com/nginx-alias-traversal/
I think i just lost my vault to an hacker, and they prop. used this method?
@BlackDex commented on GitHub (Jul 5, 2023):
Vaultwarden doesn't use nginx it self, so thats not vulnerable via that way. Also, Vaultwarden it self is not vulnerable to traversal.
I also do not see how a hacker would have stole your vault. If, then they would have had your credentials.