A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in UserTerminalRouter::getInfoForId().
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: facebook
Published: 2022-08-16T00:00:00
Updated: 2024-08-03T04:29:01.530Z
Reserved: 2022-02-11T00:00:00
Link: CVE-2022-24950
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-16T01:15:12.437
Modified: 2024-11-21T06:51:26.677
Link: CVE-2022-24950
Redhat
No data.