Bugzilla – Bug 1212224
VUL-0: CVE-2023-27706: bitwarden: Biometric key is stored in Windows Credential Manager, accessible to other local unprivileged processes
Last modified: 2023-06-12 09:32:56 UTC
CVE-2023-27706 Bitwarden Desktop v1.20.0 and above stores the biometric key in plaintext which allows a local attacker to decrypt the entire local vault. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27706 https://www.cve.org/CVERecord?id=CVE-2023-27706 https://github.com/bitwarden/clients https://github.com/bitwarden/clients/blob/8b5a223ad4ca0f89b6c9bcdbddef464d1755d2c0/apps/desktop/desktop_native/src/password/windows.rs#L16 https://hackerone.com/reports/1874155
Windows only, closing