Bug 284399 - security/vaultwarden: Security update to 1.33.0
Summary: security/vaultwarden: Security update to 1.33.0
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Michael Reifenberger
URL:
Keywords: security
Depends on: 284401
Blocks:
  Show dependency treegraph
 
Reported: 2025-01-27 19:15 UTC by foudfou
Modified: 2025-01-30 20:34 UTC (History)
5 users (show)

See Also:
bugzilla: maintainer-feedback? (mr)


Attachments
git diff for security/vaultwarden (60.72 KB, patch)
2025-01-27 19:15 UTC, foudfou
no flags Details | Diff
git diff security/vuxml (933 bytes, patch)
2025-01-27 21:51 UTC, foudfou
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description foudfou 2025-01-27 19:15:04 UTC
Created attachment 257043 [details]
git diff for security/vaultwarden

Patch for security/vaultwarden attached.

Patches for security/vuxml and www/vaultwarden-web_vault following soon.
Comment 1 Bernard Spil freebsd_committer freebsd_triage 2025-01-27 20:07:44 UTC
Note that 1.32.7 has 3 known vulnerabilities.

Can we change the dependency to require www/vaultwarden-web_vault version 2025.1.1?

That port also requires an update, I see that is 284401 is exactly that.
Comment 2 foudfou 2025-01-27 20:17:09 UTC
Hi Bernard, I created bug #284401 and added the dependency in the current ticket :)
Is there something still missing?

For the 3 known vulnerabilities, I just saw you documented them in security/vuxml https://cgit.freebsd.org/ports/commit/?id=88f39d025c1cf74638326605ac6b876f07ceb9c1
I was wondering if we should update the entry with the CVE ids published today?
Comment 3 foudfou 2025-01-27 21:51:38 UTC
Created attachment 257055 [details]
git diff security/vuxml

Adding CVE IDs to security/vuxml vaulwarden entry.

Not sure why the third vulnerability hasn't got any CVE… yet?
Comment 4 commit-hook freebsd_committer freebsd_triage 2025-01-30 20:31:44 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=75bb613dd6e8accf6a90ae0dde6e95290b94d253

commit 75bb613dd6e8accf6a90ae0dde6e95290b94d253
Author:     Michael Reifenberger <mr@FreeBSD.org>
AuthorDate: 2025-01-30 20:26:36 +0000
Commit:     Michael Reifenberger <mr@FreeBSD.org>
CommitDate: 2025-01-30 20:26:36 +0000

    security/vaultwarden: Security update to 1.33.0

    Also added CVE IDs to security/vuxml vaulwarden entry.

    PR:              284399
    Reported by:     foudfou

 security/vaultwarden/Makefile                      |   3 +-
 security/vaultwarden/Makefile.crates               | 140 +++++-----
 security/vaultwarden/distinfo                      | 286 +++++++++++----------
 .../vaultwarden/files/patch-rust-1.84.0 (gone)     |  57 ----
 security/vuxml/vuln/2025.xml                       |   7 +-
 5 files changed, 231 insertions(+), 262 deletions(-)
Comment 5 Michael Reifenberger freebsd_committer freebsd_triage 2025-01-30 20:34:55 UTC
Done.

Thanks!