CVE-2020-12477: Teampass

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.

Affected products

  • Teampass Teampass: version 2.1.27.36 only

Published 2020-04-29. Last modified 2026-06-17.