The easiest, and most secure way to access and protect all of your infrastructure.
AGPL-3.0 License
Published by russjones almost 6 years ago
Teleport 2.7.8 contains two security fixes
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones almost 6 years ago
Teleport 3.1.2 contains a security fix. We strongly encourage anyone running Teleport 3.1.1 to upgrade.
Due to the flaw in internal RBAC verification logic, a compromised node, trusted cluster or authenticated non-privileged user can craft special request to Teleport's internal auth server API to elevate the privileges and gain administrative access to the Teleport cluster.
This vulnerability could be only exploited using previously authenticated clients, there is no known way to exploit this vulnerability outside the cluster by non-authenticated clients.
To mitigate the issue, auth servers have to be upgraded.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones almost 6 years ago
Teleport 3.0.3 contains a security fix. We strongly encourage anyone running Teleport 3.0.2 to upgrade.
Due to the flaw in internal RBAC verification logic, a compromised node, trusted cluster or authenticated non-privileged user can craft special request to Teleport's internal auth server API to elevate the privileges and gain administrative access to the Teleport cluster.
This vulnerability could be only exploited using previously authenticated clients, there is no known way to exploit this vulnerability outside the cluster by non-authenticated clients.
To mitigate the issue, auth servers have to be upgraded.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones almost 6 years ago
Teleport 2.7.7 contains a security fix. We strongly encourage anyone running Teleport 2.7.6 to upgrade.
Due to the flaw in internal RBAC verification logic, a compromised node, trusted cluster or authenticated non-privileged user can craft special request to Teleport's internal auth server API to elevate the privileges and gain administrative access to the Teleport cluster.
This vulnerability could be only exploited using previously authenticated clients, there is no known way to exploit this vulnerability outside the cluster by non-authenticated clients.
To mitigate the issue, auth servers have to be upgraded.
Also upgraded Go to 1.11.4 to mitigate CVE-2018-16875: CPU denial of service in chain validation Go.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones almost 6 years ago
Teleport 2.6.10 contains a security fix. We strongly encourage anyone running Teleport 2.6.9 to upgrade.
Due to the flaw in internal RBAC verification logic, a compromised node, trusted cluster or authenticated non-privileged user can craft special request to Teleport's internal auth server API to elevate the privileges and gain administrative access to the Teleport cluster.
This vulnerability could be only exploited using previously authenticated clients, there is no known way to exploit this vulnerability outside the cluster by non-authenticated clients.
To mitigate the issue, auth servers have to be upgraded.
Also upgraded Go to 1.11.4 to mitigate CVE-2018-16875: CPU denial of service in chain validation Go.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones almost 6 years ago
Teleport 3.1.1 contains a security fix. We strongly encourage anyone running Teleport 3.1.0 to upgrade.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by russjones almost 6 years ago
Teleport 3.0.2 contains a security fix. We strongly encourage anyone running Teleport 3.0.1 to upgrade.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by russjones almost 6 years ago
This is a major Teleport release with a focus on backwards compatibility, stability, and bug fixes. Some of the changes:
-o
to improve OpenSSH interoperability. #2330
tsh
. #1693
scp
when using the Web UI. #2300
For the full list of changes, see #26.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by russjones almost 6 years ago
Pre-releases are not production ready, use at your own risk!
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by russjones about 6 years ago
This release of Teleport contains a bug fix.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones about 6 years ago
This release of Teleport contains a bug fix.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by russjones about 6 years ago
This is a major Teleport release which introduces support for Kubernetes clusters. In addition to this new feature this release includes several usability and performance improvements listed below.
tsh login
can retreive and install certificates for both Kubernetes and SSH at the same time.kubectl
commands, including recording of the sessions if kubectl exec
command was interactive.For more information about Kubernetes support, take a look at the Kubernetes and SSH Integration Guide
public_addr
setting which allows them to be hosted behind NAT/Load Balancers. #1793
etcd
back-end has been updated to implement 3.3+ protocol. See the upgrading notes below.tsh ls
or the web UI no longer shows nodes that the currently logged in user has no access to. #1954
tsh
client on Windows. Note: only tsh login
command is implemented. #1996.-i
flag to tsh login
is now guarantees to be non-interactive. #2221
scp
implementation in "recording proxy" mode did not work correctly. #2176
tsh ls
now works correctly when executed on a remote/trusted cluster #2204
The lists of improvements and bug fixes above mention only the significant changes, please take a look at the complete list on Github for more.
Follow the recommended upgrade procedure to upgrade to this version.
WARNING: if you are using Teleport with the etcd back-end, make sure your
etcd
version is 3.3 or newer prior to upgrading to Teleport 3.0.
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by russjones about 6 years ago
Pre-releases are not production ready, use at your own risk!
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by klizhentas about 6 years ago
Pre-releases are not production ready, use at your own risk!
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by klizhentas about 6 years ago
This release of Teleport focuses on bugfixes.
This release of Teleport focuses on bugfixes.
/tmp/multipart-
files #2250
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.
Published by klizhentas about 6 years ago
Pre-releases are not production ready, use at your own risk!
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by klizhentas about 6 years ago
Pre-releases are not production ready, use at your own risk!
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by klizhentas about 6 years ago
NOT READY FOR PRODUCTION Use at your own risk!
Published by russjones about 6 years ago
Pre-releases are not production ready, use at your own risk!
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download
Published by russjones about 6 years ago
This release of Teleport focuses on bugfixes.
client_idle_timeout
. #2166
node_labels
in roles. #2136
Download the current and previous releases of Teleport at https://gravitational.com/teleport/download.