CVE-2017-15055: Improper Privilege Management
(updated )
TeamPass does not properly enforce item access control when requesting items.queries.php
. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the file attachments of an arbitrary item, copy the password of an arbitrary item to the copy/paste
buffer, access the history of an arbitrary item, and edit attributes of an arbitrary directory.
References
Detect and mitigate CVE-2017-15055 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →