Back

MEDIUM

openssh: potential command injection via shell metacharacters

Published Dec 18, 2023

Description

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.

Affected products

Remediation

Red Hat statement

The ability to execute OS commands is dependent on what quoting is present in the user-supplied ssh_config directive. However, it is generally the user's responsibility to validate arguments passed to SSH.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (21)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Dec 18, 2023
Updated Jul 14, 2026
Reserved Dec 18, 2023

CISA Vulnrichment

Updated Aug 15, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Dec 18, 2023
Bugzilla 2255271

ENISA EUVD

Assigner mitre
Published Dec 18, 2023
Updated Jul 14, 2026

GitHub

No data