{"id":"GHSA-x7m9-mv49-fv73","summary":"Vaultwarden vulnerable to user impersonation","details":"An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.","aliases":["CVE-2024-55225"],"modified":"2025-01-10T18:38:01Z","published":"2025-01-09T21:31:32Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-01-09T23:13:58Z","nvd_published_at":"2025-01-09T21:15:29Z","cwe_ids":["CWE-276","CWE-863"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55225"},{"type":"WEB","url":"https://github.com/dani-garcia/vaultwarden/commit/20d9e885bfcd7df7828d92c6e59ed5fe7b40a879"},{"type":"WEB","url":"https://github.com/dani-garcia/vaultwarden/commit/37c14c3c69b244ec50f5c62b4c9260171607c1d8"},{"type":"PACKAGE","url":"https://github.com/dani-garcia/vaultwarden"},{"type":"WEB","url":"https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4"},{"type":"WEB","url":"https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5"},{"type":"WEB","url":"https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5"}],"affected":[{"package":{"name":"vaultwarden","ecosystem":"crates.io","purl":"pkg:cargo/vaultwarden"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.32.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-x7m9-mv49-fv73/GHSA-x7m9-mv49-fv73.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}