HIGH7.5
GHSA-fv48-hjhp-94c7
Incorrect Authorization in TeamPass
Details
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nilsteampassnet/teampass
Introduced in:
0No fixed version published yet for nilsteampassnet/teampass (composer). Pin to a known-safe version or switch to an alternative.