Back

MEDIUM

The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS

Published Feb 20, 2005

Description

The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.

Affected products

Remediation

Red Hat statement

Permitting TCP forwarding is the expected and known default configuration. If it is not desired, it can disabled using the AllowTcpForwarding option in the /etc/ssh/sshd_config configuration file. However, only disabling TCP forwarding does not improve security unless users are also denied shell access. For more information, see man sshd_config.

Metrics

Weaknesses (0)

No CWE recorded.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2005
Updated Aug 8, 2024
Reserved Feb 21, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a