rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rssh | Nov 8, 2019 | Feb 4, 2019 |
| Amazon_linux | — | Upgrade rssh | Dec 20, 2019 | Feb 4, 2019 |
| Debian | — | Upgrade rssh | Feb 14, 2019 | Feb 14, 2019 |
| Freebsd | — | Upgrade rssh | Mar 7, 2019 | Mar 6, 2019 |
| Gentoo Linux | — | Upgrade app-shells/rssh. | Jul 28, 2020 | Feb 4, 2019 |
| Ubuntu | — | Upgrade rssh | Apr 24, 2019 | Feb 4, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub