CVE-2022-41925
Last modified
CVE-2022-41925 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale environment variables. In the Tailscale client, the peer API was vulnerable to DNS rebinding. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale environment variables. In the Tailscale client, the peer API was vulnerable to DNS rebinding. This allowed an attacker-controlled website visited by the node to rebind DNS for the peer API to an attacker-controlled DNS server, and then making peer API requests in the client, including accessing the node’s Tailscale environment variables. An attacker with access to the peer API on a node could use that access to read the node’s environment variables, including any credentials or secrets stored in environment variables. This may include Tailscale authentication keys, which could then be used to add new nodes to the user’s tailnet. The peer API access could also be used to learn of other nodes in the tailnet or send files via Taildrop. All Tailscale clients prior to version v1.32.3 are affected. Upgrade to v1.32.3 or later to remediate the issue.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tailscale | Tailscale | < 1.32.3 |
References
- https://emily.id.au/tailscaleExploit, Technical Description, Third Party Advisory
- https://github.com/tailscale/tailscale/security/advisories/GHSA-qccm-wmcq-pwr6Third Party Advisory
- https://tailscale.com/security-bulletins/#ts-2022-005Vendor Advisory
- https://emily.id.au/tailscaleExploit, Technical Description, Third Party Advisory
- https://github.com/tailscale/tailscale/security/advisories/GHSA-qccm-wmcq-pwr6Third Party Advisory
- https://tailscale.com/security-bulletins/#ts-2022-005Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41925?
How severe is CVE-2022-41925?
How do I fix CVE-2022-41925?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-4192Use after free in Live Caption in Google Chrome prior to 108…8.8
- CVE-2022-41920Lancet is a general utility library for the go programming l…8.8
- CVE-2022-41921Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2022-41922`yiisoft/yii` before version 1.1.27 are vulnerable to Remote…9.8
- CVE-2022-41923Grails Spring Security Core plugin is vulnerable to privileg…9.8
- CVE-2022-41924A vulnerability identified in the Tailscale Windows client a…9.6
- CVE-2022-41926Nextcould talk android is the android OS implementation of t…5.5
- CVE-2022-41927XWiki Platform is vulnerable to Cross-Site Request Forgery (…7.4
- CVE-2022-41928XWiki Platform vulnerable to Improper Neutralization of Dire…8.8
- CVE-2022-41929org.xwiki.platform:xwiki-platform-oldcore is missing authori…4.9
- CVE-2022-4193Insufficient policy enforcement in File System API in Google…8.8
- CVE-2022-41930org.xwiki.platform:xwiki-platform-user-profile-ui is missing…8.2
Are you affected by CVE-2022-41925?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
