Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade opensshUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-clients | Jun 17, 2020 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssh-askpassUpgrade opensshUpgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-clients | Apr 16, 2020 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssh-clientsUpgrade openssh-serverUpgrade openssh-askpassUpgrade openssh-keycatUpgrade openssh | Mar 24, 2020 | Aug 28, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssh-clientsUpgrade openssh-keycatUpgrade opensshUpgrade openssh-ldapUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-cavs | Feb 26, 2020 | Aug 28, 2018 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Nov 9, 2018 | Aug 28, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 28, 2018 |
| Suse | — | Upgrade openssh-debugsourceUpgrade openssh-helpers-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-openssl1-helpersUpgrade opensshUpgrade openssh-askpass-gnomeUpgrade openssh-askpass-gnome-debuginfoUpgrade openssh-openssl1Upgrade openssh-cavsUpgrade openssh-helpersUpgrade openssh-fipsUpgrade openssh-askpassUpgrade openssh-debuginfo | Oct 30, 2018 | Aug 28, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub