Description
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1463 | The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. |
Github GHSA |
GHSA-fv48-hjhp-94c7 | Incorrect Authorization in TeamPass |
References
| Link | Providers |
|---|---|
| https://github.com/nilsteampassnet/TeamPass/issues/2761 |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:56:52.043Z
Reserved: 2020-04-29T00:00:00.000Z
Link: CVE-2020-12477
No data.
Status : Modified
Published: 2020-04-29T22:15:12.577
Modified: 2024-11-21T04:59:46.843
Link: CVE-2020-12477
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA