Vulnerabilities > CVE-2020-15879 - Server-Side Request Forgery (SSRF) vulnerability in Bitwarden Server 1.35.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |