Количество 3
Количество 3
CVE-2026-71959
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.
CVE-2026-71959
Bitwarden Server before 2026.7.2 does not verify that the caller is a ...
GHSA-m2wp-hqw2-j56m
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-71959 Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log. | CVSS3: 5.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-71959 Bitwarden Server before 2026.7.2 does not verify that the caller is a ... | CVSS3: 5.8 | 0% Низкий | около 1 месяца назад | |
GHSA-m2wp-hqw2-j56m Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log. | CVSS3: 5.8 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу