Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2prh-86cw-fm96

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

EPSS

Процентиль: 17%
0.0025
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 4.2
ubuntu
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 5.4
redhat
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
nvd
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
msrc
24 дня назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
debian
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location o ...

EPSS

Процентиль: 17%
0.0025
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-23