Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xf3-5hp7-xqqg

Опубликовано: 25 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper token validation leading to code execution in Teleport

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

Пакеты

Наименование

github.com/gravitational/teleport

go
Затронутые версииВерсия исправления

< 8.3.17

8.3.17

Наименование

github.com/gravitational/teleport

go
Затронутые версииВерсия исправления

>= 9.0.0, < 9.3.13

9.3.13

Наименование

github.com/gravitational/teleport

go
Затронутые версииВерсия исправления

>= 10.0.0, < 10.1.2

10.1.2

EPSS

Процентиль: 97%
0.31616
Средний

8.8 High

CVSS3

Дефекты

CWE-20
CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

EPSS

Процентиль: 97%
0.31616
Средний

8.8 High

CVSS3

Дефекты

CWE-20
CWE-77