Sploitus

CVE-2024-39924

1 known exploit for CVE-2024-39924

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.

Affected products
Vaultwarden
Dani-garcia Vaultwarden
= 1.30.3
CVSS 3.1
8.8 HIGH
EPSS
13.3% (96th percentile)
Weakness
CWE-276
NVD status
Analyzed
Published
2024-09-13
CVE-2024-39924 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-39924

Proof-of-concept code and exploit modules indexed by Sploitus