An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssh | Mar 21, 2024 | Mar 12, 2022 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Mar 13, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade openssh-clientsUpgrade opensshUpgrade openssh-server | Aug 2, 2022 | Mar 13, 2022 |
| Huawei Euleros 2_0_sp12 | — | Upgrade openssh-serverUpgrade opensshUpgrade openssh-clients | Oct 8, 2024 | Mar 13, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssh-serverUpgrade opensshUpgrade openssh-clients | Jul 11, 2022 | Mar 13, 2022 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 8.9 | Mar 21, 2022 | Mar 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub