Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-32728

Опубликовано: 10 апр. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

A flaw was found in OpenSSH. In affected versions of sshd, the DisableForwarding directive does not fully adhere to the intended functionality as documented. Specifically, it fails to disable X11 and agent forwarding, which may allow unintended access under certain configurations.

Меры по смягчению последствий

To mitigate this vulnerability, explicitly disable X11 and agent forwarding in your SSH configuration (sshd_config) using: X11Forwarding no AllowAgentForwarding no

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-440
https://bugzilla.redhat.com/show_bug.cgi?id=2358767openssh: OpenSSH SSHD Agent Forwarding and X11 Forwarding

EPSS

Процентиль: 6%
0.00027
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

CVSS3: 4.3
nvd
2 месяца назад

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

CVSS3: 3.8
msrc
около 2 месяцев назад

Описание отсутствует

CVSS3: 4.3
debian
2 месяца назад

In sshd in OpenSSH before 10.0, the DisableForwarding directive does n ...

suse-cvrf
около 1 месяца назад

Security update for openssh

EPSS

Процентиль: 6%
0.00027
Низкий

4.3 Medium

CVSS3