Teleport allows remote authentication bypass
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.8epss 7.8%
exploitation probability
7.8%top 6% of all CVEs
observed exploitation
nono source reports it
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
gravitational · teleport