CVE Database
/

CVE-2022-24950

Back to search

CVE-2022-24950

Published: Aug 16, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().

VendorProductVersions

Jason Gauci

Eternal Terminal

affected
unspecified - < 6.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now