Vulnerability Description
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teampass | Teampass | <= 2.1.27.0 |
Related Weaknesses (CWE)
References
- https://github.com/nilsteampassnet/TeamPass/issues/2495Third Party Advisory
- https://github.com/nilsteampassnet/TeamPass/issues/2495Third Party Advisory
FAQ
What is CVE-2019-1000001?
CVE-2019-1000001 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. Th...
How severe is CVE-2019-1000001?
CVE-2019-1000001 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-1000001?
Check the references section above for vendor advisories and patch information. Affected products include: Teampass Teampass.