Back

MEDIUM

openssh: Public key information leak

Published Sep 15, 2021

Description

OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product

Affected products

Remediation

Red Hat statement

Although a CVE was assigned upstream and Red Hat doesn't consider it to be a security flaw and won't receive any patch, also the CVE was made as disputed by MITRE. Considering that Red Hat is closing this flaw as NOTABUG.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 15, 2021
Updated May 29, 2026
Reserved Sep 15, 2021
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 7, 2016