DuoConnect SSH Connection Vulnerability
DuoConnect SSH Connection Vulnerability
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
The Duo Product team has fixed the issue by updating DuoConnect to version 1.1.1, which rejects relay configurations that do not specify an HTTPS-based relay. A DNG instance will automatically instruct users to install the latest version of DuoConnect. Duo administrators do not need to perform any manual updates unless their DNG is not able to connect to the internet to download the new version of the software. In that case, administrators should instruct end-users to download the latest DuoConnect version directly using the links below. Steps required for end-user remediation: Update DuoConnect: End-users will need to update DuoConnect once prompted to do so by the DNG (users will be prompted to upgrade DuoConnect during authentication in their browser from July 7, 2020 onwards). The updated version of DuoConnect can alternatively be downloaded directly from the following locations at any time: Windows - https://dl.duosecurity.com/DuoConnect-1.1.1.msi macOS - https://dl.duosecurity.com/DuoConnect-1.1.1.pkg Linux - https://dl.duosecurity.com/DuoConnect-1.1.1.tar.gz The signature of DuoConnect installer files can be verified at https://duo.com/docs/checksums. End-users will need to update their DuoConnect SSH configuration if they receive the error message shown below: Error: Invalid URL: relay scheme http://server-ssh.example.com invalid: must be https Update the SSH configuration: Locate the http relay in the SSH configuration e.g. “ProxyCommand duoconnect -host=%h:%p