Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

Vaultwarden

95 Topics 812 Posts
  • Vaultwarden - Package Updates

    Pinned Locked
    79
    0 Votes
    79 Posts
    50k Views
    Package UpdatesP
    [1.25.0] Update vaultwarden to 1.36.0 Full Changelog SSO Login CSRF GHSA-pfp2-jhgq-6hg5 GHSA-w6h6-8r66-hcv7 User/Organization Enumeration GHSA-hxqh-ff5p-wfr3 SSO existing-user binding GHSA-j4j8-gpvj-7fqr GHSA-6x5c-84vm-5j56 SSRF via Icon Endpoint GHSA-72vh-x5jq-m82g Archiving of items is available https://bitwarden.com/blog/keep-your-vault-tidy-with-item-archiving/ https://bitwarden.com/nl-nl/help/managing-items/#archive Web Vault updated to v2026.4.1 SSO fallback to UserInfo preferred_username by @Timshel in #7128 Add support for archiving items by @matt-aaron in #6916 Fix favicon fetching to check all icon links instead of just the first one by @Shocker in #6880 fix: return Err instead of panic on unknown cipher atype in to_json() by @mango766 in #7068
  • Vaultwarden fails to start after update – DB migration error (SSO)

    Solved
    73
    2 Votes
    73 Posts
    8k Views
    jdaviescoatesJ
    @james said: Please follow these steps if you have this issue: Can this script be run on the working version I reverted to, or do I need to update to the broken version and then run it? Edit: yes, it seems fixing the db and then updating also works fine.
  • Custom Variables Are Not Saved On /app/data/config.json

    4
    1 Votes
    4 Posts
    209 Views
    I
    James, I found the solution. I forget to add {} before and after the variable, that makes my config.json error. Now, it's solved. { "signups_allowed": false, "invitations_allowed": true, }
  • This topic is deleted!

    0
    3 Votes
    0 Posts
    323 Views
    No one has replied
  • 7 Votes
    3 Posts
    357 Views
    T
    Thanks for the heads up - no impact on vaultwarden apparently: https://github.com/dani-garcia/vaultwarden/discussions/7126
  • This topic is deleted!

    0
    1 Votes
    0 Posts
    1 Views
    No one has replied
  • Cloudron documentation outdated? Bitwarden now supports SSO

    22
    1
    0 Votes
    22 Posts
    5k Views
    J
    @inibudi the latest vaultwarden package already supports Cloudron OpenID. Thanks for getting back though.
  • [NOTICE] You are using a plain text `ADMIN_TOKEN` which is insecure.

    2
    1 Votes
    2 Posts
    341 Views
    jamesJ
    Hello @dimtar We have a documentation for exactly that. See https://docs.cloudron.io/packages/vaultwarden#admin
  • Registration possible, even if it has been disabled

    5
    0 Votes
    5 Posts
    601 Views
    KubernetesK
    Yes, it is set to false. Maybe I was tricked because I had one Domain whitelisted. I don't remember if the "Register"-Link was always there. Would love to hide it. It seems, that the disabled registration does work. Sorry for alerting...
  • This topic is deleted!

    0
    0 Votes
    0 Posts
    2 Views
    No one has replied
  • "An unexpected error has occurred" due to missing /api/tasks endpoint

    2
    3 Votes
    2 Posts
    1k Views
    girishG
    This is getting updated - https://git.cloudron.io/packages/vaultwarden-app/-/merge_requests/20
  • Vaultwarden Branding

    6
    2 Votes
    6 Posts
    3k Views
    andreasduerenA
    By the way, Vaultwarden itself is fine with assets living elsewhere. You can use surfer to host for example logo files and then drop the link in the user.vaultwarden.scss.hbs file.
  • SIGNUPS_ALLOWED=false doesn't work for me.

    14
    1 Votes
    14 Posts
    3k Views
    girishG
    @jdaviescoates the comment in the package says there are some values that can only be set in env . But I cannot find what they are . AFAICT, it is safe to empty it out.
  • Errors in log and net responding clients

    Solved
    18
    1 Votes
    18 Posts
    6k Views
    I
    @girish Hello i confirm, the update fix the issue thank you
  • Insecure KDF iterations settings

    11
    1 Votes
    11 Posts
    4k Views
    potemkin_aiP
    @necrevistonnezr my installation is quite old - that's correct. Thanks for checking in! @girish , thank you for the doc's reference! Guess it might make sense to stress that during the installation, as well as an offer to increase KDF up to 2 mln (as per Bitwarden docs as well).
  • Bitwarden extension UI Refresh

    1
    3 Votes
    1 Posts
    695 Views
    No one has replied
  • Vaultwarden 1.32.7 released with security fixes

    1
    2 Votes
    1 Posts
    324 Views
    No one has replied
  • Bitwarden will get NATIVE mobile apps very soon

    4
    6 Votes
    4 Posts
    2k Views
    L
    https://bitwarden.com/download/
  • Vaultwarden 1.32.4 released to fix several CVE Reports

    Solved
    2
    2 Votes
    2 Posts
    808 Views
    nebulonN
    The package is already out by now.
  • Vaultwarden 1.32.0 released with several security fixes

    Solved
    4
    4 Votes
    4 Posts
    2k Views
    C
    @necrevistonnezr Thank you for providing this information. It is really nice to know that although I am not a German taxpayer they are watching my back as well. Much appreciated. @joseph And as usual, Cloudron team is on the ball patching quickly so any exposure is minimized. Well done!