Логотип exploitDog
bind:CVE-2022-36633
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-36633

Количество 2

Количество 2

nvd логотип

CVE-2022-36633

больше 3 лет назад

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-6xf3-5hp7-xqqg

больше 3 лет назад

Improper token validation leading to code execution in Teleport

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-36633

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

CVSS3: 8.8
32%
Средний
больше 3 лет назад
github логотип
GHSA-6xf3-5hp7-xqqg

Improper token validation leading to code execution in Teleport

CVSS3: 8.8
32%
Средний
больше 3 лет назад

Уязвимостей на страницу