Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-38599

Disclosure Date: December 08, 2022 (last updated February 24, 2025)
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
Attacker Value
Unknown

CVE-2022-36633

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.
Attacker Value
Unknown

CVE-2021-41393

Disclosure Date: September 18, 2021 (last updated November 28, 2024)
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.
Attacker Value
Unknown

CVE-2021-41394

Disclosure Date: September 18, 2021 (last updated November 28, 2024)
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.
Attacker Value
Unknown

CVE-2021-41395

Disclosure Date: September 18, 2021 (last updated November 28, 2024)
Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.