PT-2019-1685 · None+1 · Rssh+1
Published
2019-01-30
·
Updated
2025-03-19
·
CVE-2019-1000018
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rssh version 2.3.4
Description
The issue is related to a command injection vulnerability in the allowscp permission, which can result in local command execution. This can be exploited by an authorized SSH user with the allowscp permission. The vulnerability is due to the lack of input data sanitization, allowing an attacker to execute arbitrary shell commands.
Recommendations
For version 2.3.4, consider restricting the use of the allowscp permission until a patch is available. As a temporary workaround, limit the access of authorized SSH users to minimize the risk of exploitation.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu
Rssh