CVE-2022-24950
Last modified
CVE-2022-24950 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eternal Terminal Project | Eternal Terminal | < 6.2.0 |
References
- https://github.com/MisterTea/EternalTerminal/commit/900348bb8bc96e1c7ba4888ac8480f643c43d3c3Patch, Third Party Advisory
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-85gw-pchc-4rf3Exploit, Third Party Advisory
- https://github.com/MisterTea/EternalTerminal/commit/900348bb8bc96e1c7ba4888ac8480f643c43d3c3Patch, Third Party Advisory
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-85gw-pchc-4rf3Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-24950?
How severe is CVE-2022-24950?
How do I fix CVE-2022-24950?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-24945Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-24946Improper Resource Locking vulnerability in Mitsubishi Electr…7.5
- CVE-2022-24947Apache JSPWiki user preferences form is vulnerable to CSRF a…8.8
- CVE-2022-24948A carefully crafted user preferences for submission could tr…6.1
- CVE-2022-24949A privilege escalation to root exists in Eternal Terminal pr…7.5
- CVE-2022-2495Cross-site Scripting (XSS) - Stored in GitHub repository mic…4.8
- CVE-2022-24951A race condition exists in Eternal Terminal prior to version…7
- CVE-2022-24952Several denial of service vulnerabilities exist in Eternal T…6.5
- CVE-2022-24953The Crypt_GPG extension before 1.6.7 for PHP does not preven…5.3
- CVE-2022-24954Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 1…9.8
- CVE-2022-24955Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 1…9.8
- CVE-2022-24956An issue was discovered in Shopware B2B-Suite through 4.4.1.…6.5
Are you affected by CVE-2022-24950?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
