Description
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1468 | Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default. |
Github GHSA |
GHSA-gmr7-m73x-6c9q | Missing Authorization in TeamPass |
References
| Link | Providers |
|---|---|
| https://github.com/nilsteampassnet/TeamPass/issues/2765 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:35:13.763Z
Reserved: 2020-04-10T00:00:00.000Z
Link: CVE-2020-11671
No data.
Status : Modified
Published: 2020-05-04T14:15:13.230
Modified: 2024-11-21T04:58:22.160
Link: CVE-2020-11671
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA