PT-2019-1685 · None+1 · Rssh+1
Publicado
2019-01-30
·
Atualizado
2025-03-19
·
CVE-2019-1000018
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rssh version 2.3.4
Description
The issue is related to a command injection vulnerability in the allowscp permission, which can result in local command execution. This can be exploited by an authorized SSH user with the allowscp permission. The vulnerability is due to the lack of input data sanitization, allowing an attacker to execute arbitrary shell commands.
Recommendations
For version 2.3.4, consider restricting the use of the allowscp permission until a patch is available. As a temporary workaround, limit the access of authorized SSH users to minimize the risk of exploitation.
Exploit
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ubuntu
Rssh