Chisel Server Security Vulnerability Affects Authenticated Connections
CVE-2024-43798
What is CVE-2024-43798?
The vulnerability in Chisel, a popular TCP/UDP tunneling tool developed by Jpillora, lies in its failure to properly utilize the AUTH environment variable that is designed to set user credentials. This oversight permits unauthenticated users to connect to the Chisel server, regardless of any credentials intended to control access. The risk is compounded by Chisel's common application as an entry point into private networks, which might expose sensitive services to unauthorized access. Attackers can exploit this weakness to execute man-in-the-middle (MITM) attacks, rerouting traffic from a remote port through the compromised Chisel server. Users of Chisel are urged to upgrade to version 1.10.0 or later to mitigate this vulnerability.
Affected Version(s)
chisel < 1.10.0
