A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: facebook

Published: 2022-08-16T00:00:00

Updated: 2023-02-16T00:00:00

Reserved: 2022-02-11T00:00:00


Link: CVE-2022-24950

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-08-16T01:15:12.437

Modified: 2023-02-16T19:15:11.753


Link: CVE-2022-24950

JSON object: View

cve-icon Redhat Information

No data.

CWE