bitwarden / clients

Bitwarden client apps (web, browser extension, desktop, and cli).
https://bitwarden.com
Other
9.31k stars 1.26k forks source link

Chrome extension fills password in `masterPasswordHint` field of webUI #6461

Open bilogic opened 1 year ago

bilogic commented 1 year ago

Steps To Reproduce

  1. I create an entry in my vault to login to autofill credentials at the BW login screen
  2. After I login I head to /#/settings/security/change-password
  3. My password gets exposed in plaintext in the masterPasswordHint field

Expected Result

My password should not be exposed in the masterPasswordHint field

Actual Result

My password gets exposed in plaintext in the masterPasswordHint field, probably because the tag's ID has the word password in it

Screenshots or Videos

image

My password is exposed in the plaintext field

Additional Context

No response

Operating System

Windows

Operating System Version

Windows 10

Web Browser

Chrome

Browser Version

Version 117.0.5938.92 (Official Build) (64-bit)

Build Version

Version: 2023.9.1

Issue Tracking Info

Neonwarden commented 1 year ago

Hi there,

Thank you for your report!

I was able to reproduce this issue, and I have flagged this to our engineering team.

If you wish to add any further information/screenshots/recordings etc., please feel free to do so at any time - our engineering team will be happy to review these.

Thanks once again!