#VU27507 Improper Authentication in TeamPass - CVE-2020-12477
Published: May 4, 2020 / Updated: April 14, 2023
TeamPass
Nils Laumaillé
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in the REST API functions. A remote authenticated attacker can bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the "getIp" function.