Количество 2
Количество 2
CVE-2022-36633
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.
GHSA-6xf3-5hp7-xqqg
Improper token validation leading to code execution in Teleport
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-36633 Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload. | CVSS3: 8.8 | 32% Средний | больше 3 лет назад | |
GHSA-6xf3-5hp7-xqqg Improper token validation leading to code execution in Teleport | CVSS3: 8.8 | 32% Средний | больше 3 лет назад |
Уязвимостей на страницу