Description
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29703 | A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId(). |
References
History
No history.
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2024-08-03T04:29:01.530Z
Reserved: 2022-02-11T00:00:00.000Z
Link: CVE-2022-24950
No data.
Status : Modified
Published: 2022-08-16T01:15:12.437
Modified: 2024-11-21T06:51:26.677
Link: CVE-2022-24950
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD