World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Tmate-ssh-server | Tmate | * | 2.3.0 (including) | 
| Tmate-ssh-server | Ubuntu | devel | * | 
| Tmate-ssh-server | Ubuntu | esm-apps/jammy | * | 
| Tmate-ssh-server | Ubuntu | esm-apps/noble | * | 
| Tmate-ssh-server | Ubuntu | hirsute | * | 
| Tmate-ssh-server | Ubuntu | impish | * | 
| Tmate-ssh-server | Ubuntu | jammy | * | 
| Tmate-ssh-server | Ubuntu | kinetic | * | 
| Tmate-ssh-server | Ubuntu | lunar | * | 
| Tmate-ssh-server | Ubuntu | mantic | * | 
| Tmate-ssh-server | Ubuntu | noble | * | 
| Tmate-ssh-server | Ubuntu | oracular | * | 
| Tmate-ssh-server | Ubuntu | plucky | * | 
| Tmate-ssh-server | Ubuntu | questing | * | 
| Tmate-ssh-server | Ubuntu | trusty | * | 
| Tmate-ssh-server | Ubuntu | xenial | * |