PT-2024-26127 · Sshproxy · Sshproxy

Fdiakh

·

Published

2024-05-14

·

Updated

2024-06-04

·

CVE-2024-34713

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions sshproxy versions prior to 1.6.3
Description The issue allows any user authorized to connect to an SSH server using sshproxy to inject options to the ssh command executed by sshproxy. This affects all versions of sshproxy prior to 1.6.3.
Recommendations For versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue. As a temporary workaround, consider using the force command option in sshproxy.yaml, but note that this is rarely relevant.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34713
GHSA-JMQP-37M5-49WH
GO-2024-2836

Affected Products

Sshproxy