Warm users about access key leakage in access logs #1105

Closed
opened 2026-04-06 01:35:39 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @rwjack on 6/7/2024

Not really a bug, but I think the docs should provide info about this: https://github.com/bitwarden/clients/issues/4290

I just saw that from v1.29.0, WSS is enabled by default, which means all access tokens and encrypted data is being stored in plaintext in reverse proxy access logs, unless the proxy is configured to filter out such requests.

*Originally created by @rwjack on 6/7/2024* Not really a bug, but I think the docs should provide info about this: https://github.com/bitwarden/clients/issues/4290 I just saw that from v1.29.0, WSS is enabled by default, which means all access tokens and encrypted data is being stored in plaintext in reverse proxy access logs, unless the proxy is configured to filter out such requests.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/vaultwarden#1105