-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nilsteampassnet/teampass | composer | < 3.0.10 | 3.0.10 |
The vulnerability stems from missing 'index.html' files in multiple directories, allowing directory listing exposure. The patch adds these files to prevent unauthorized access to directory contents. This is a server configuration/structural issue rather than a specific function vulnerability. No code functions were modified in the fix - only static HTML files were added to sensitive directories to block directory enumeration. The exposure occurs at the web server level when default index files are absent, not through exploitable application functions.
KEV Misses 88% of Exploited CVEs- Get the report