{"id":"GHSA-x36g-4629-xp9v","summary":"TeamPass External Control of File Name or Path vulnerability","details":"External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.","aliases":["CVE-2023-1070"],"modified":"2023-11-08T04:11:13.854647Z","published":"2023-02-27T18:32:09Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-02-28T23:27:43Z","nvd_published_at":"2023-02-27T16:15:00Z","cwe_ids":["CWE-73"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1070"},{"type":"WEB","url":"https://github.com/nilsteampassnet/teampass/commit/0af3574caba27a61b16dc25c94fa51ae12d2d967"},{"type":"PACKAGE","url":"https://github.com/nilsteampassnet/teampass"},{"type":"WEB","url":"https://huntr.dev/bounties/318bfdc4-7782-4979-956f-9ba2cc44889c"}],"affected":[{"package":{"name":"nilsteampassnet/teampass","ecosystem":"Packagist","purl":"pkg:composer/nilsteampassnet/teampass"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.0.23"}]}],"versions":["2.1.21","2.1.26","2.1.27","3.0.0","3.0.0.10","3.0.0.11"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-x36g-4629-xp9v/GHSA-x36g-4629-xp9v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"}]}