CVE-2023-6004

MEDIUM

libssh >=0.8.0 <0.9.8 - OS Command Injection via ProxyCommand or ProxyJump Hostname Parameter

Title source: llm
STIX 2.1

Description

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.

Scores

CVSS v3 4.8
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (4)
fedoraproject/fedora 38
libssh/libssh 0.8.0 - 0.9.8
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
Published Jan 03, 2024
Tracked Since Feb 18, 2026