Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35386

Опубликовано: 02 апр. 2026
Источник: debian

Описание

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:10.3p1-1package
opensshfixed1:10.0p1-7+deb13u3trixiepackage
opensshfixed1:9.2p1-2+deb12u10bookwormpackage

Примечания

  • https://www.openssh.org/releasenotes.html#10.3p1

Связанные уязвимости

CVSS3: 3.6
ubuntu
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
redhat
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
nvd
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
msrc
4 месяца назад

Описание отсутствует

CVSS3: 3.6
github
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.