openssh: potential command injection via shell metacharacters
Published Dec 18, 2023
6.5
MEDIUMCVSS 3.1
EPSS 19.75%
Description
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Affected products
No data.
Configuration 2
- 10.0
- 11.0
- 12.0
No data.
RHODF-4.15-RHEL-9
odf4/cephcsi-rhel9:v4.15.0-37
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/mcg-core-rhel9:v4.15.0-68
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/mcg-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/mcg-rhel9-operator:v4.15.0-39
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/ocs-client-console-rhel9:v4.15.0-58
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/ocs-client-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/ocs-client-rhel9-operator:v4.15.0-13
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/ocs-metrics-exporter-rhel9:v4.15.0-81
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/ocs-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/ocs-rhel9-operator:v4.15.0-79
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-cli-rhel9:v4.15.0-22
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-console-rhel9:v4.15.0-57
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-cosi-sidecar-rhel9:v4.15.0-6
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-csi-addons-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-csi-addons-rhel9-operator:v4.15.0-15
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-csi-addons-sidecar-rhel9:v4.15.0-15
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-multicluster-console-rhel9:v4.15.0-54
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-multicluster-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-multicluster-rhel9-operator:v4.15.0-10
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-must-gather-rhel9:v4.15.0-26
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odf-rhel9-operator:v4.15.0-19
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odr-cluster-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odr-hub-operator-bundle:v4.15.0-158
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/odr-rhel9-operator:v4.15.0-21
Fixed · RHSA-2024:1383
RHODF-4.15-RHEL-9
odf4/rook-ceph-rhel9-operator:v4.15.0-103
Fixed · RHSA-2024:1383
Red Hat Enterprise Linux 8
openssh-0:8.0p1-19.el8_9.2
Fixed · RHSA-2024:0606
Red Hat Enterprise Linux 8
openssh-0:8.0p1-19.el8_9.2
Fixed · RHSA-2024:0606
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
openssh-0:8.0p1-7.el8_4.2
Fixed · RHSA-2026:22329
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
openssh-0:8.0p1-7.el8_4.2
Fixed · RHSA-2026:22329
Red Hat Enterprise Linux 8.6 Extended Update Support
openssh-0:8.0p1-15.el8_6.3
Fixed · RHSA-2024:0429
Red Hat Enterprise Linux 8.8 Extended Update Support
openssh-0:8.0p1-19.el8_8.2
Fixed · RHSA-2024:0594
Red Hat Enterprise Linux 9
openssh-0:8.7p1-34.el9_3.3
Fixed · RHSA-2024:1130
Red Hat Enterprise Linux 9
openssh-0:8.7p1-34.el9_3.3
Fixed · RHSA-2024:1130
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
openssh-0:8.7p1-13.el9_0.1
Fixed · RHSA-2026:1790
Red Hat Enterprise Linux 9.2 Extended Update Support
openssh-0:8.7p1-30.el9_2.3
Fixed · RHSA-2024:0455
Red Hat Enterprise Linux 6
openssh
Out of support scope
Red Hat Enterprise Linux 7
openssh
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| RHODF-4.15-RHEL-9 | odf4/cephcsi-rhel9:v4.15.0-37 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/mcg-core-rhel9:v4.15.0-68 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/mcg-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/mcg-rhel9-operator:v4.15.0-39 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/ocs-client-console-rhel9:v4.15.0-58 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/ocs-client-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/ocs-client-rhel9-operator:v4.15.0-13 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/ocs-metrics-exporter-rhel9:v4.15.0-81 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/ocs-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/ocs-rhel9-operator:v4.15.0-79 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-cli-rhel9:v4.15.0-22 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-console-rhel9:v4.15.0-57 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-cosi-sidecar-rhel9:v4.15.0-6 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-csi-addons-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-csi-addons-rhel9-operator:v4.15.0-15 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-csi-addons-sidecar-rhel9:v4.15.0-15 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-multicluster-console-rhel9:v4.15.0-54 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-multicluster-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-multicluster-rhel9-operator:v4.15.0-10 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-must-gather-rhel9:v4.15.0-26 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odf-rhel9-operator:v4.15.0-19 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odr-cluster-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odr-hub-operator-bundle:v4.15.0-158 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/odr-rhel9-operator:v4.15.0-21 | Fixed | RHSA-2024:1383 |
| RHODF-4.15-RHEL-9 | odf4/rook-ceph-rhel9-operator:v4.15.0-103 | Fixed | RHSA-2024:1383 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-19.el8_9.2 | Fixed | RHSA-2024:0606 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-19.el8_9.2 | Fixed | RHSA-2024:0606 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | openssh-0:8.0p1-7.el8_4.2 | Fixed | RHSA-2026:22329 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | openssh-0:8.0p1-7.el8_4.2 | Fixed | RHSA-2026:22329 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | openssh-0:8.0p1-15.el8_6.3 | Fixed | RHSA-2024:0429 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | openssh-0:8.0p1-19.el8_8.2 | Fixed | RHSA-2024:0594 |
| Red Hat Enterprise Linux 9 | openssh-0:8.7p1-34.el9_3.3 | Fixed | RHSA-2024:1130 |
| Red Hat Enterprise Linux 9 | openssh-0:8.7p1-34.el9_3.3 | Fixed | RHSA-2024:1130 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | openssh-0:8.7p1-13.el9_0.1 | Fixed | RHSA-2026:1790 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | openssh-0:8.7p1-30.el9_2.3 | Fixed | RHSA-2024:0455 |
| Red Hat Enterprise Linux 6 | openssh | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssh | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The ability to execute OS commands is dependent on what quoting is present in the user-supplied ssh_config directive. However, it is generally the user's responsibility to validate arguments passed to SSH.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (21)
- http://seclists.org/fulldisclosure/2024/Mar/21 mailing-list
- http://www.openwall.com/lists/oss-security/2023/12/26/4 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2025/10/07/1
- http://www.openwall.com/lists/oss-security/2025/10/12/1
- https://access.redhat.com/security/cve/CVE-2023-51385 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255271 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-769027.html
- https://cert-portal.siemens.com/productcert/html/ssa-794697.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-56106 Advisory
- https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a Patch
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-51385
- https://security.gentoo.org/glsa/202312-17 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240105-0005/
- https://support.apple.com/kb/HT214084
- https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-51385
- https://www.debian.org/security/2023/dsa-5586 vendor-advisoryThird Party Advisory
- https://www.openssh.com/txt/release-9.6 Release Notes
- https://www.openwall.com/lists/oss-security/2023/12/18/2 Mailing ListRelease Notes
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data