HIGH8.8
GHSA-6xf3-5hp7-xqqg
Improper token validation leading to code execution in Teleport
Quick fix
GHSA-6xf3-5hp7-xqqg — github.com/gravitational/teleport: upgrade to the fixed version with the command below.
go get github.com/gravitational/teleport@v8.3.17Details
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gravitational/teleport
Introduced in:
0Fixed in: 8.3.17Fix
go get github.com/gravitational/teleport@v8.3.17Go/github.com/gravitational/teleport
Introduced in:
9.0.0Fixed in: 9.3.13Fix
go get github.com/gravitational/teleport@v9.3.13Go/github.com/gravitational/teleport
Introduced in:
10.0.0Fixed in: 10.1.2Fix
go get github.com/gravitational/teleport@v10.1.2References
- https://nvd.nist.gov/vuln/detail/CVE-2022-36633[ADVISORY]
- https://github.com/gravitational/teleport/pull/14726[WEB]
- https://github.com/gravitational/teleport/pull/14726/commits/46c23b9b64b944d1e82d2c8a79083f291ffdd3b6[WEB]
- https://github.com/gravitational/teleport[PACKAGE]
- https://github.com/gravitational/teleport/releases/tag/v10.1.2[WEB]
- https://github.com/gravitational/teleport/releases/tag/v8.3.17[WEB]
- https://github.com/gravitational/teleport/releases/tag/v9.3.13[WEB]
- https://packetstormsecurity.com/files/168137/Teleport-9.3.6-Command-Injection.html[WEB]
- http://packetstormsecurity.com/files/168477/Teleport-10.1.1-Remote-Code-Execution.html[WEB]