CVE-2023-27706

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
09/06/2023
Last modified:
06/01/2025

Description

Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitwarden:bitwarden:*:*:*:*:desktop:*:*:* 2023.4.0 (excluding)