PT-2026-68310 · Unknown · Boringproxy
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
boringproxy versions prior to 0.10.1
Description
Authenticated low-privileged users with tunnel-creation permissions can perform a newline injection. By providing a percent-encoded newline character in the
domain parameter of the tunnel creation endpoint, an attacker can inject arbitrary lines into the server account's SSH authorized keys file. This allows the insertion of an unrestricted public key to obtain persistent shell access, enabling the attacker to read cleartext credentials from the database file, including all user tokens, tunnel private keys, and TLS certificates.Recommendations
Update boringproxy to a version newer than 0.10.0.
Avoid using the
domain parameter in the tunnel creation endpoint until the software is updated.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Boringproxy