Update vaultwarden/server Docker tag to v1.33.0 #45
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refs/pull/45/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.32.7->1.33.0Release Notes
dani-garcia/vaultwarden (vaultwarden/server)
v1.33.0Compare Source
Security Fixes
This release contains security fixes for the following advisories.
And we strongly advice to update as soon as possible.
This vulnerability is only possible if you do not have an
ADMIN_TOKENconfigured and open links or pages you should not trust anyway. Ensure you have anADMIN_TOKENconfigured to keep your admin environment save.This vulnerability is only possible if someone was able to gain access to your Vaultwarden Admin Backend. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell command. It then also needed to craft a special favicon image which would have the commands embedded to run during for example sending a test email.
This vulnerability affects all users who have multiple Organizations and users which are able to create a new organization or have admin or owner rights on at least one organization. The attacker does need to know the Organization UUID of the Organization it want's to attack or compromise though.
Notable changes
Admins and Owners probably want to check and verify if the rights are still correct.
This allows you to verify an OCI image or even the
vaultwardenbinary located within the OCI image.These vulnerabilities affects
What's Changed
inline-menu-positioning-improvementsfeature flag by @Ephemera42 in https://github.com/dani-garcia/vaultwarden/pull/5313New Contributors
Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.32.7...1.33.0
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.