VDB
Sign up
HIGH8.8

GHSA-6xf3-5hp7-xqqg

Improper token validation leading to code execution in Teleport

Quick fix

GHSA-6xf3-5hp7-xqqg — github.com/gravitational/teleport: upgrade to the fixed version with the command below.

go get github.com/gravitational/teleport@v8.3.17

Details

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/gravitational/teleport
Introduced in: 0Fixed in: 8.3.17
Fixgo get github.com/gravitational/teleport@v8.3.17
Go/github.com/gravitational/teleport
Introduced in: 9.0.0Fixed in: 9.3.13
Fixgo get github.com/gravitational/teleport@v9.3.13
Go/github.com/gravitational/teleport
Introduced in: 10.0.0Fixed in: 10.1.2
Fixgo get github.com/gravitational/teleport@v10.1.2

References