Vulnerabilities > Goteleport

DATE CVE VULNERABILITY TITLE RISK
2022-12-08 CVE-2022-38599 Exposure of Resource to Wrong Sphere vulnerability in Goteleport Teleport 3.2.2/3.5.6/3.6.3
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
network
low complexity
goteleport CWE-668
6.5
2022-08-24 CVE-2022-36633 OS Command Injection vulnerability in Goteleport Teleport
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution.
network
low complexity
goteleport CWE-78
8.8
2021-09-18 CVE-2021-41393 Unspecified vulnerability in Goteleport Teleport
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.
network
low complexity
goteleport
critical
9.8
2021-09-18 CVE-2021-41394 Unspecified vulnerability in Goteleport Teleport
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.
network
low complexity
goteleport
5.3
2021-09-18 CVE-2021-41395 Unspecified vulnerability in Goteleport Teleport
Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.
network
low complexity
goteleport
6.5