CVE-2022-24950
Last modified
CVE-2022-24950 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eternal Terminal Project | Eternal Terminal | < 6.2.0 |
References
- https://github.com/MisterTea/EternalTerminal/commit/900348bb8bc96e1c7ba4888ac8480f643c43d3c3Patch, Third Party Advisory
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-85gw-pchc-4rf3Exploit, Third Party Advisory
- https://github.com/MisterTea/EternalTerminal/commit/900348bb8bc96e1c7ba4888ac8480f643c43d3c3Patch, Third Party Advisory
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-85gw-pchc-4rf3Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-24950?
How severe is CVE-2022-24950?
How do I fix CVE-2022-24950?
Are you affected by CVE-2022-24950?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
