Bitwarden


reports in last 90 days

4

disclosed resolved issues

1

disclosed informative issues

0

disclosed N/A issues

Listed on HackerOne — Updated on 2019/10/15

Bug Title Bug Type Found By Report Info Report Status

High Tracking Bitwarden firefox addon users

None supplied kmodi Issue was not triaged


Time to close: 0 Days and 10 hours
Resolved

Low Vulnerable exported broadcast receiver

Violation of Secure Design Principles b3nac Issue was not triaged


Time to close: 0 Days and 3 hours
Resolved

Low Mailgun misconfiguration on email.bitwarden.com

Business Logic Errors babayaga_ Issue was not triaged


Time to close: 0 Days and 2 hours
Resolved

Medium Organization Admin Privilege Escalation To Owner

Business Logic Errors rhynorater Time to triage: 0 Days and 1 hours


Time to close: 0 Days and 0 hours
Resolved

No rating Export vault feature is vulnerable to CSV injection

OS Command Injection kenziy Issue was not triaged


Time to close: 0 Days and 17 hours
Informative