Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's position is that "Auto-fill on page load" is not enabled by default.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T12:23:30.807Z
Reserved: 2023-03-08T00:00:00
Link: CVE-2023-27974
Updated: 2024-08-02T12:23:30.807Z
Status : Modified
Published: 2023-03-09T00:15:09.930
Modified: 2024-11-21T07:53:50.983
Link: CVE-2023-27974
No data.
OpenCVE Enrichment
No data.
Weaknesses