Vulnerability Description
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teampass | Teampass | 2.1.27.36 |
Related Weaknesses (CWE)
References
- https://github.com/nilsteampassnet/TeamPass/issues/2761ExploitThird Party Advisory
- https://github.com/nilsteampassnet/TeamPass/issues/2761ExploitThird Party Advisory
FAQ
What is CVE-2020-12477?
CVE-2020-12477 is a vulnerability with a CVSS score of 7.5 (HIGH). The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
How severe is CVE-2020-12477?
CVE-2020-12477 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12477?
Check the references section above for vendor advisories and patch information. Affected products include: Teampass Teampass.