Loading HuntDB...

When uploading attachments, unencrypted file names are made available to the server

B
Bitwarden
Submitted None

Team Summary

Official summary from Bitwarden

Certain Bitwarden clients were inadvertently posting raw filenames to the server when saving new attachments. The server was discarding this value and properly storing the encrypted filename, however, a malicious server could glean some information from the filename if it were inclined. The issue has been patched.

Reported by jjlin

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Missing Encryption of Sensitive Data