CVE-2023-38840

Published
View on NVD ↗
CVSS v3
5.5
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

The desktop vault (Windows, macOS, & Linux).
GitHubGitHub
3.54K
A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.
GitHubGitHub
42