Описание
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Mailing ListRelease Notes
- Third Party Advisory
- Third Party Advisory
- Mailing ListRelease Notes
Уязвимые конфигурации
Конфигурация 1Версия от 8.9 (включая) до 9.3 (исключая)
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:o:netapp:brocade_fabric_operating_system:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:solidfire_element_os:-:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00107
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 2 лет назад
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
CVSS3: 9.1
redhat
больше 2 лет назад
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
CVSS3: 9.8
debian
больше 2 лет назад
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without ...
CVSS3: 9.8
github
больше 2 лет назад
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints.
EPSS
Процентиль: 30%
0.00107
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo