CVE-2019-1000001
CRITICALTeamPass <2.1.27 - Info Disclosure
Title source: llmDescription
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage.
Scores
CVSS v3
9.8
EPSS
0.0034
EPSS Percentile
56.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
published
Affected Products (2)
teampass/teampass
< 2.1.27.0
nilsteampassnet/teampass
Packagist
Timeline
Published
Feb 04, 2019
Tracked Since
Feb 18, 2026