GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment) This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong

  • osanna@thebrainbin.org
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    1 day ago

    one thing I’m not willing to self host is vault/bitwarden. My whole life is based in my password manager. I imagine Bitwarden inc has a lot better security than me, and if I lose access to it I’m stuffed.

    • keyez@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      Bitwarden was the second thing I ever self hosted. On a local server on a UPS and hasn’t really been an issue across 7 years. Every so often I save an encrypted JSON on my main laptop to use with keepass if there’s ever an issue where the server is down for a while.

    • nopermissions@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      20 hours ago

      Had this exact thing happen to me. I was hosting vaultwarden on a raspberry pi and then it fell over. My client devices had caged versions of my vault, but I couldn’t make changes to it. I quickly moved over to Bitwarden and it’s been fantastic.