ZeroHour

CVE-2022-24950

PoC
CVSS 3.1
7.5 high
EPSS
1%p68
Published
()
Modified
Description

A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().

Vendors
eternal terminal project
Products
eternal terminal
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.