ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
严重 CVSS 9.8
摘要
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://security.gentoo.org/glsa/202307-01 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230413-0008/ Third Party Advisory
- https://www.debian.org/security/2023/dsa-5586
- https://www.openwall.com/lists/oss-security/2023/03/15/8 Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://security.gentoo.org/glsa/202307-01 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230413-0008/ Third Party Advisory
- https://www.debian.org/security/2023/dsa-5586
- https://www.openwall.com/lists/oss-security/2023/03/15/8 Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
时间线
- nvd_ingest NVD