GHSA-76cc-p55w-63g3

Suggest an improvement
Source
https://github.com/advisories/GHSA-76cc-p55w-63g3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-76cc-p55w-63g3
Withdrawn
2024-01-23T12:50:23Z
Published
2024-01-03T21:29:09Z
Modified
2024-09-06T21:40:26Z
Summary
Withdrawn Advisory: Teleport Access List owners can escalate their privileges
Details

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability affects a binary, not a library in a supported ecosystem. Therefore, users of the library should not receive alerts. This link is maintained to preserve external references.

Original Description

Impact

Access Lists are a new feature introduced in Teleport 14 and currently under preview. An issue was discovered that allows an Access List Owner to assign arbitrary permissions, including permissions to themselves which could result in privilege escalation.

Patches

Fixed in version 14.2.4 and 13.4.13

Database specific
{
    "severity": "CRITICAL",
    "nvd_published_at": null,
    "github_reviewed_at": "2024-01-03T21:29:09Z",
    "cwe_ids": [],
    "github_reviewed": true
}
References

Affected packages

Go / github.com/gravitational/teleport

Package

Name
github.com/gravitational/teleport
View open source insights on deps.dev
Purl
pkg:golang/github.com/gravitational/teleport

Affected ranges

Type
SEMVER
Events
Introduced
14.0.0
Fixed
14.2.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json"

Go / github.com/gravitational/teleport

Package

Name
github.com/gravitational/teleport
View open source insights on deps.dev
Purl
pkg:golang/github.com/gravitational/teleport

Affected ranges

Type
SEMVER
Events
Introduced
13.0.0
Fixed
13.4.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json"