Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41617

Опубликовано: 26 сент. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4
CVSS3: 7

Описание

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1:9.0p1-1ubuntu7
esm-infra-legacy/trusty

needed

esm-infra/bionic

needed

esm-infra/focal

not-affected

1:8.2p1-4ubuntu0.11
esm-infra/xenial

released

1:7.2p2-4ubuntu2.10+esm2
fips-preview/jammy

not-affected

1:8.9p1-3
fips-updates/bionic

needed

fips-updates/focal

released

1:8.2p1-4ubuntu0.fips.0.11
fips-updates/jammy

not-affected

1:8.9p1-3

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-apps/jammy

ignored

esm-apps/noble

ignored

esm-infra-legacy/trusty

DNE

focal

ignored

hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 67%
0.00535
Низкий

4.4 Medium

CVSS2

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
почти 4 года назад

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

CVSS3: 7
nvd
почти 4 года назад

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

CVSS3: 7
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7
debian
почти 4 года назад

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default c ...

suse-cvrf
больше 3 лет назад

Security update for openssh

EPSS

Процентиль: 67%
0.00535
Низкий

4.4 Medium

CVSS2

7 High

CVSS3