Goteleport develops Teleport, a privileged-access management and identity-aware access proxy platform deployed in infrastructure where remote authentication and session control are critical. The durable vulnerability signal centers on access-control and command-injection weaknesses, reflecting the sensitive role this product plays in mediating authentication and command execution across distributed systems.
The number and severity of CVEs published that impact products developed by Goteleport over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36633HIGH Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with | Aug 24, 2022 | 8.8 | 68 | NO | YES |
CVE-2021-41393CRITICAL Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations. | Sep 18, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-38599MEDIUM Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface. | Dec 8, 2022 | 6.5 | 24 | NO | NO |
CVE-2021-41395MEDIUM Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username. | Sep 18, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-41394MEDIUM Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations. | Sep 18, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goteleport.
Media articles that mention a CVE ID that affects a product developed by Goteleport — matched by CVE ID, not by vendor name.