When uploading attachments, unencrypted file names are made available to the server
B
Bitwarden
Submitted None
Team Summary
Official summary from Bitwarden
Certain Bitwarden clients were inadvertently posting raw filenames to the server when saving new attachments. The server was discarding this value and properly storing the encrypted filename, however, a malicious server could glean some information from the filename if it were inclined. The issue has been patched.
Actions:
Reported by
jjlin
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Missing Encryption of Sensitive Data