Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.
Link | Tags |
---|---|
https://github.com/gravitational/teleport/releases/tag/v6.2.12 | release notes third party advisory patch |
https://github.com/gravitational/teleport/releases/tag/v7.1.1 | release notes third party advisory patch |