Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities Detected in TeamPass Repository #4399

Open
thevietronin opened this issue Oct 7, 2024 · 8 comments
Open

Vulnerabilities Detected in TeamPass Repository #4399

thevietronin opened this issue Oct 7, 2024 · 8 comments

Comments

@thevietronin
Copy link

Hi @nilsteampassnet, I have identified several high vulnerabilities in the TeamPass repository. I would like to know the appropriate process to submit a detailed report for these issues. Additionally, I would appreciate guidance on how to request a CVE (Common Vulnerabilities and Exposures) identifier for these vulnerabilities. Thank you so much!

@corentin-soriano
Copy link
Contributor

@tvnnn Are these vulnerabilities still present on 3.1.2?
https://github.com/nilsteampassnet/TeamPass/releases/tag/3.1.2

@thevietronin
Copy link
Author

Hi @corentin-soriano, these vulnerabilities are still present in version 3.1.2. I discovered them just a few hours ago.

@corentin-soriano
Copy link
Contributor

@tvnnn you can send them to Nils: [email protected]
Can you also send me a copy? [email protected]

@thevietronin
Copy link
Author

@corentin-soriano Sure, I will send each email containing the details of each vulnerability i’ve found. I will also send any additional vulnerabilities I discover in the latest version in the future.

@corentin-soriano
Copy link
Contributor

Thank you!

@otsmr
Copy link

otsmr commented Nov 11, 2024

Hey @corentin-soriano and @nilsteampassnet :), I also found a vulnerability (tested against the master branch) and informed you about it by email (29.10 and 05.11), but haven't received any reply yet, so I wanted to ask if the emails are being checked and if you could give a short feedback? Thank you very much :)

@corentin-soriano
Copy link
Contributor

It was in spams folder...

I'll look this week.
Thanks for reporting this!

@nilsteampassnet
Copy link
Owner

Didn't received it on my side.
@corentin-soriano can you forward it to me please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants