Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssh-askpassUpgrade opensshUpgrade openssh-serverUpgrade openssh-clientsUpgrade openssh-keycat | Jun 17, 2020 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-serverUpgrade openssh-askpassUpgrade openssh | Apr 16, 2020 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssh-askpassUpgrade openssh-keycatUpgrade openssh-serverUpgrade opensshUpgrade openssh-clients | Mar 24, 2020 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssh-keycatUpgrade openssh-clientsUpgrade opensshUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-serverUpgrade openssh-cavs | Feb 26, 2020 | Aug 28, 2018 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Nov 9, 2018 | Aug 28, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 28, 2018 |
| Suse | — | Upgrade openssh-askpass-gnome-debuginfoUpgrade openssh-debuginfoUpgrade openssh-helpersUpgrade openssh-askpassUpgrade openssh-askpass-gnomeUpgrade openssh-cavsUpgrade openssh-openssl1Upgrade openssh-fipsUpgrade openssh-openssl1-helpersUpgrade openssh-helpers-debuginfoUpgrade openssh-cavs-debuginfoUpgrade opensshUpgrade openssh-debugsource | Oct 30, 2018 | Aug 28, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub