VDB
Sign up
HIGH7.5

GHSA-2rhg-hqq9-8xjh

TeamPass information exposure vulnerability

Quick fix

GHSA-2rhg-hqq9-8xjh — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^3.0.10

Details

TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 3.0.10
Fixcomposer require nilsteampassnet/teampass:^3.0.10

References