Описание
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Меры по смягчению последствий
Make sure you are not executing connections with untrusted username inputs.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libssh | Fix deferred | ||
| Red Hat Enterprise Linux 8 | libssh | Affected | ||
| Red Hat Enterprise Linux 9 | libssh | Fix deferred | ||
| Red Hat Hardened Images | libssh-main-0.12.1-4.hum1 | Fixed | RHSA-2026:42922 | 21.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.9 Low
CVSS3
Связанные уязвимости
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Libssh: libssh: information disclosure via proxycommand %r username expansion
A flaw was found in libssh. A malicious username expanded through %r i ...
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
EPSS
3.9 Low
CVSS3