Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump vaultwarden to 1.32.7 #1561

Merged
merged 1 commit into from
Dec 20, 2024
Merged

bump vaultwarden to 1.32.7 #1561

merged 1 commit into from
Dec 20, 2024

Conversation

sjorge
Copy link
Contributor

@sjorge sjorge commented Dec 20, 2024

Seems another security related release.

Security Fixes

We have yet a few other security fixes for this release. We discovered that groups were able to be edited by any admin from any organization because the organization was not validated or used within the query. This could potentially allow an admin from other organizations to modify, or delete groups from any organization if they know the uuid of the group.
We suggest people to update a.s.a.p. to mitigate this risk.

-- https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.7

Haven't given this a build in a VM as it seems my build zone is broken. But past updates seemed to have went fine without issue.

@citrus-it citrus-it merged commit 31ca313 into omniosorg:master Dec 20, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants