Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44xq-r8h3-q4q6

Опубликовано: 18 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

EPSS

Процентиль: 35%
0.00426
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
redhat
почти 3 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
nvd
почти 3 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
msrc
8 месяцев назад

In ssh-agent in OpenSSH before 9.6 certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys these constraints are only applied to the first key even if a PKCS#11 token returns multiple keys.

CVSS3: 5.5
debian
почти 3 года назад

In ssh-agent in OpenSSH before 9.6, certain destination constraints ca ...

EPSS

Процентиль: 35%
0.00426
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-284