Vulnerability Description
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Goteleport | Teleport | 3.2.2 |
Related Weaknesses (CWE)
References
- http://teleport.comProduct
- https://gist.github.com/arleyna/20d858e11c48984d00926fa8cc0c2722ExploitThird Party Advisory
- http://teleport.comProduct
- https://gist.github.com/arleyna/20d858e11c48984d00926fa8cc0c2722ExploitThird Party Advisory
FAQ
What is CVE-2022-38599?
CVE-2022-38599 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
How severe is CVE-2022-38599?
CVE-2022-38599 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38599?
Check the references section above for vendor advisories and patch information. Affected products include: Goteleport Teleport.