CVE-2020-12477: Teampass
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
Affected products
- Teampass Teampass: version 2.1.27.36 only
Published 2020-04-29. Last modified 2026-06-17.