<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Vaultwarden 1.32.0 released with several security fixes]]></title><description><![CDATA[<p dir="auto"><a href="https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0</a></p>
<blockquote>
<p dir="auto">This release has several CVE Reports fixed and we recommend everybody to update to the latest version as soon as possible.</p>
<p dir="auto">CVE-2024-39924 Fixed via #4715<br />
CVE-2024-39925 Fixed via #4837<br />
CVE-2024-39926 Fixed via #4737</p>
</blockquote>
]]></description><link>https://forum.cloudron.io/topic/12272/vaultwarden-1-32-0-released-with-several-security-fixes</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 03:09:26 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/12272.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 11 Aug 2024 20:01:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Vaultwarden 1.32.0 released with several security fixes on Thu, 17 Oct 2024 02:10:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> Thank you for providing this information.  It is really nice to know that although I am not a German taxpayer they are watching my back as well.  Much appreciated.  <a class="plugin-mentions-user plugin-mentions-a" href="/user/joseph" aria-label="Profile: joseph">@<bdi>joseph</bdi></a> And as usual, Cloudron team is on the ball patching quickly so any exposure is minimized.  Well done!</p>
]]></description><link>https://forum.cloudron.io/post/95730</link><guid isPermaLink="true">https://forum.cloudron.io/post/95730</guid><dc:creator><![CDATA[crazybrad]]></dc:creator><pubDate>Thu, 17 Oct 2024 02:10:09 GMT</pubDate></item><item><title><![CDATA[Reply to Vaultwarden 1.32.0 released with several security fixes on Wed, 16 Oct 2024 19:22:21 GMT]]></title><description><![CDATA[<p dir="auto">BTW the security flaws were discovered as part of CAOS, a code review program run by the German Federal Office for Information Security: <a href="https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/Codeanalyse-KeePass-Vaultwarden_241014.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/Codeanalyse-KeePass-Vaultwarden_241014.html</a> (German)</p>
<blockquote>
<p dir="auto">As part of the project for the "Code Analysis of Open Source Software" (CAOS 3.0), the Federal Office for Information Security (BSI) examined the password managers KeePass and Vaultwarden for their security characteristics. Two security vulnerabilities with the "high" rating were identified in Vaultwarden.</p>
<p dir="auto">In most cases, cyber attacks can be attributed to errors in the program code of the affected applications. The CAOS project helps to identify and eliminate common vulnerabilities and risks. The BSI checked the source code of the password managers KeePass and Vaultwarden for possible defects with mgm security partners GmbH. The BSI has communicated vulnerabilities found in the process to the  developers concerned as part of a responsible disclosure procedure. They have analyzed the weak points and have already reacted. The now published results are a combination of source code review, dynamic analysis and interface analysis in the areas of network interfaces, protocols and standards.</p>
<p dir="auto">In cooperation with mgm security partners GmbH, the BSI started the project "Code Analysis of Open Source Software" (CAOS) in 2021. The task of the project is the vulnerability analysis with the aim of increasing the security of open source software. The project is intended to support developers in the creation of secure software applications and increase confidence in open source software. The focus is on applications that are increasingly used by authorities or private individuals. This new publication is the result of the successor project "Code Analysis of Open Source Software" (CAOS 3.0).</p>
<p dir="auto">In order to increase the security of open source software in the future, further code analyses are planned. The project for the "Code Analysis of Open Source Software" will be continued. The results will also be published on the BSI website after a responsible disclosure procedure. The procedure allows developers a reasonable period of time to fix security vulnerabilities before publishing them.</p>
</blockquote>
]]></description><link>https://forum.cloudron.io/post/95728</link><guid isPermaLink="true">https://forum.cloudron.io/post/95728</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Wed, 16 Oct 2024 19:22:21 GMT</pubDate></item><item><title><![CDATA[Reply to Vaultwarden 1.32.0 released with several security fixes on Mon, 12 Aug 2024 07:13:59 GMT]]></title><description><![CDATA[<p dir="auto">I guess you mean 1.32.0 <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=223f9defb2f" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /> Fixed title</p>
]]></description><link>https://forum.cloudron.io/post/92609</link><guid isPermaLink="true">https://forum.cloudron.io/post/92609</guid><dc:creator><![CDATA[joseph]]></dc:creator><pubDate>Mon, 12 Aug 2024 07:13:59 GMT</pubDate></item></channel></rss>