GHSA-237r-mx84-7x8c

    Dashboard / Vulnerabilities / GHSA-237r-mx84-7x8c

    GHSA-237r-mx84-7x8c

    Published: 16 Sept 2022Last Modified: 18 Nov 2024

    Summary: VNCAuthProxy authentication bypass vulnerability

    Details: OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC session. A remote attacker with network access to the proxy server could leverage this vulnerability to connect to VNC servers protected by the proxy server without providing any authentication credentials. Exploitation of this issue requires that the proxy server is currently accepting connections for the target VNC server.

    Affected packages

    Package

    Name: vncauthproxy

    Purl: pkg:pypi/vncauthproxy

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.2.0

    Affected versions

    0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-237r-mx84-7x8c | CVE-DB