1
Missing authentication for the /icons/ endpoint
Source: dani-garcia/vaultwarden#2115 · opened by @l4rm4nd
Subject of the issue I would assume that the /icons endpoint of vaultwarden also requires user authentication. Currently, any external user is able to query the endpoint and identify valid icons without being authenticated to the webvault. This may allow someone to enumerate vault url entries or sites that have been stored. One can disable the icon download, but it is kinda handy as for visual aspects. I don't know whether this is an issue at all. Not a security one from my perspective, but might introduce some privacy concerns if remote people can enumerate whether a vault has some adult or illegal sites stored. What do you think? Deployment environment Vaultwarden runs as Docker container on my RPi4 (ARM). Deployed within portainer and compose file. Exposed via an nginx reverse proxy. • vaultwarden version: Version 1.23.0 • Install method: Portainer Docker Compose • Clients used: Any client with access to the web vault (http protocol) S…
No pledges yet. Be the first to back this.
Comments
Similar requests
Set up the upstream icons server
1 vote · 0 comments
Feature Request: Support login_hint Parameter for SSO OAuth Authorization Requests
3 votes · 0 comments
Get vaultwarden to "proxy" or pull icos from a pre-cache? ie. not accessing internet
1 vote · 0 comments
Feature Request: MCP Wallet/Server Integration for AI Agent Authentication
2 votes · 0 comments
Bitwarden Version and Config Endpoint
2 votes · 0 comments
No comments yet.