← Back

CVE-2022-24950

nvd nist
Published: Aug 16, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().

Affected (1)

Eternal Terminal
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.2.0

References (6)

Timeline

No history available yet.