TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4934 TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage.
Github GHSA Github GHSA GHSA-q9qr-h33g-fw3j TeamPass Storing Passwords in a Recoverable Format vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T03:00:19.367Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-1000001

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-02-04T21:29:00.643

Modified: 2024-11-21T04:17:38.863

Link: CVE-2019-1000001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.