Improper Control of Generation of Code ('Code Injection') Affecting github.com/gravitational/teleport/lib/srv package, versions <12.4.32 >=13.0.0 <13.4.14 >=14.0.0 <14.2.4
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMGRAVITATIONALTELEPORTLIBSRV-6143556
- published 4 Jan 2024
- disclosed 3 Jan 2024
- credit Tener
How to fix?
Upgrade github.com/gravitational/teleport/lib/srv
to version 12.4.32, 13.4.14, 14.2.4 or higher.
Overview
Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection') via user-provided environment values on macOS agents. An attacker can execute unexpected code through user-supplied environment variables.
References
CVSS Scores
version 3.1