Alpine: multiple vaultwarden packages: security update to 1.32.0

high Tenable Self-Hosted Container Security Plugin ID 427538

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified
in the authentication and authorization process of the endpoint responsible for altering the metadata of
an emergency access. It permits an attacker with granted emergency access to escalate their privileges by
changing the access level and modifying the wait time. Consequently, the attacker can gain full control
over the vault (when only intended to have read access) while bypassing the necessary wait period.
(CVE-2024-39924)

- An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for
members who leave an organization. As a result, the shared organization key is not rotated when a member
departs. Consequently, the departing member, whose access should be revoked, retains a copy of the
organization key. Additionally, the application fails to adequately protect some encrypted data stored on
the server. Consequently, an authenticated user could gain unauthorized access to encrypted data of any
organization, even if the user is not a member of the targeted organization. However, the user would need
to know the corresponding organizationId. Hence, if a user (whose access to an organization has been
revoked) already possesses the organization key, that user could use the key to decrypt the leaked data.
(CVE-2024-39925)

- An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS)
or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This
potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then
executed or rendered in the context of an administrator's browser when viewing the injected content.
However, it is important to note that the default Content Security Policy (CSP) of the application blocks
most exploitation paths, significantly mitigating the potential impact. (CVE-2024-39926)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-39924

https://security.alpinelinux.org/vuln/CVE-2024-39925

https://security.alpinelinux.org/vuln/CVE-2024-39926

Plugin Details

Severity: High

ID: 427538

Version: Revision 1.5

Type: Local

Published: 5/16/2025

Updated: 6/1/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: Low

Base Score: 3.5

Temporal Score: 2.7

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2024-39926

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2024-39924

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/12/2024

Reference Information

CVE: CVE-2024-39924, CVE-2024-39925, CVE-2024-39926