CVE-2017-15053: Improper Privilege Management
(updated )
TeamPass does not properly enforce manager access control when requesting roles.queries.php
. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role.
References
Detect and mitigate CVE-2017-15053 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →