CVE-2022-36633High· 8.8▾ MidnightPoC availableImproper token validation leading to code execution in Teleport
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 10.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
49%
49% → 50%
Exploit-DB (last check)
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.
github.com/gravitational/teleport < 8.3.17github.com/gravitational/teleport >= 9.0.0, < 9.3.13github.com/gravitational/teleport >= 10.0.0, < 10.1.2Upgrade to a patched release:
github.com/gravitational/teleport 8.3.17github.com/gravitational/teleport 9.3.13github.com/gravitational/teleport 10.1.2