漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Libssh: libssh: information disclosure via proxycommand %r username expansion
Vulnerability Description
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
libssh 安全漏洞
Vulnerability Description
libssh是libssh组织开源的一个用于访问SSH服务的C语言开发包,它能够执行远程命令、文件传输,同时为远程的程序提供安全的传输通道。 libssh存在安全漏洞,该漏洞源于在ProxyCommand处理中通过%r扩展恶意用户名时可能注入shell元字符,导致暴露环境变量并引起意外的shell行为。
CVSS Information
N/A
Vulnerability Type
N/A