CVE-2024-50701

TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.
Configurations

Configuration 1 (hide)

cpe:2.3:a:teampass:teampass:*:*:*:*:*:*:*:*

History

29 Sep 2025, 17:53

Type Values Removed Values Added
CPE cpe:2.3:a:teampass:teampass:*:*:*:*:*:*:*:*
References () https://github.com/nilsteampassnet/TeamPass/commit/ddbb2d3d94085dced50c4936fd2215af88e4a88d - () https://github.com/nilsteampassnet/TeamPass/commit/ddbb2d3d94085dced50c4936fd2215af88e4a88d - Patch
References () https://github.com/nilsteampassnet/TeamPass/compare/3.1.2...3.1.3.1 - () https://github.com/nilsteampassnet/TeamPass/compare/3.1.2...3.1.3.1 - Product
References () https://github.com/nilsteampassnet/TeamPass/compare/3.1.3...3.1.3.1 - () https://github.com/nilsteampassnet/TeamPass/compare/3.1.3...3.1.3.1 - Product
Summary
  • (es) En las versiones anteriores a 3.1.3.1, al recuperar información sobre los derechos de acceso a una carpeta, TeamPass no verifica correctamente si una carpeta está en la lista de carpetas permitidas de un usuario definida por un administrador.
First Time Teampass teampass
Teampass

30 Dec 2024, 16:15

Type Values Removed Values Added
CWE CWE-266
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

30 Dec 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-30 15:15

Updated : 2025-09-29 17:53


NVD link : CVE-2024-50701

Mitre link : CVE-2024-50701

CVE.ORG link : CVE-2024-50701


JSON object : View

Products Affected

teampass

  • teampass
CWE
CWE-266

Incorrect Privilege Assignment