Описание
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | only affects 8.9 and newer |
| devel | not-affected | 1:9.3p1-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | only affects 8.9 and newer |
| esm-infra/bionic | not-affected | only affects 8.9 and newer |
| esm-infra/focal | not-affected | only affects 8.9 and newer |
| esm-infra/xenial | not-affected | only affects 8.9 and newer |
| fips-updates/bionic | not-affected | only affects 8.9 and newer |
| fips-updates/focal | not-affected | only affects 8.9 and newer |
| fips-updates/xenial | not-affected | only affects 8.9 and newer |
| fips/bionic | not-affected | only affects 8.9 and newer |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | only affects 8.9 and newer |
| devel | not-affected | only affects 8.9 and newer |
| esm-apps/bionic | not-affected | only affects 8.9 and newer |
| esm-apps/focal | not-affected | only affects 8.9 and newer |
| esm-apps/jammy | not-affected | only affects 8.9 and newer |
| focal | not-affected | only affects 8.9 and newer |
| jammy | not-affected | only affects 8.9 and newer |
| kinetic | not-affected | only affects 8.9 and newer |
| lunar | not-affected | only affects 8.9 and newer |
| mantic | not-affected | only affects 8.9 and newer |
Показывать по
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without ...
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints.
EPSS
9.8 Critical
CVSS3