Bitwarden 服务器 2025.6.0 至 2026.5.0(不含 2026.5.0)版本中, 存储过程将 参数声明为 ,而其所查询的数据库列实际存储类型为 。这一不匹配导致在 SQL Server 部署环境下,SSO(单点登录)身份标识会被静默截断为前 50 个字符。攻击者可利用此缺陷,通过构造其身份提供者的标识符以另一位组织成员的完整 50 字符标识符作为前缀,从而冒充该成员进行认证,并获取仅限受害者范围访问的令牌。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bitwarden | bitwarden server | 2025.6.0< 2026.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bitwarden | bitwarden server | 2025.6.0 ~ 2026.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet