mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-03-12 01:45:56 -05:00
[PR #4715] [MERGED] Some fixes for emergency access #7119
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/dani-garcia/vaultwarden/pull/4715
Author: @BlackDex
Created: 7/8/2024
Status: ✅ Merged
Merged: 7/8/2024
Merged by: @dani-garcia
Base:
main← Head:ea_fixes📝 Commits (1)
c1a01b6Some fixes for emergency access📊 Changes
3 files changed (+116 additions, -95 deletions)
View changed files
📝
src/api/core/accounts.rs(+6 -9)📝
src/api/core/emergency_access.rs(+90 -77)📝
src/db/models/emergency_access.rs(+20 -9)📄 Description
Headersparameter for some functions This allowed any request from allowing these endpoints by not validating the user correctly.Fixes https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39924
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.