Information Exposure Affecting nilsteampassnet/teampass package, versions <3.0.10


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.18% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-NILSTEAMPASSNETTEAMPASS-5768550
  • published9 Jul 2023
  • disclosed9 Jul 2023
  • creditUnknown

Introduced: 9 Jul 2023

CVE-2023-3553  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade nilsteampassnet/teampass to version 3.0.10 or higher.

Overview

nilsteampassnet/teampass is a password manager.

Affected versions of this package are vulnerable to Information Exposure. Teampass has directory listing by default for various endpoints that eventually discloses application-specific and user data and files.

References

CVSS Scores

version 3.1