CVE-2022-24950
Summary
| CVE | CVE-2022-24950 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-16 01:15:00 UTC |
| Updated | 2023-02-16 19:15:00 UTC |
| Description | A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId(). |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eternal Terminal Project | Eternal Terminal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Eternal Terminal SSH Authorization Socket Hijacking · Advisory · metaredteam/external-disclosures · GitHub | MISC | github.com | |
| red fixes (#468) · MisterTea/EternalTerminal@900348b · GitHub | CONFIRM | github.com | |
| oss-security - EternalTerminal: Review report and findings (predictable /tmp file paths and file permission issues, 3 CVEs) | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.