CVE Database
/

CVE-2023-35812

Back to search

CVE-2023-35812

Published: Apr 3, 2024

Modified: Mar 25, 2025

PUBLISHED

CVSS v3.1

5.3

MEDIUM

Description

An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used, there is no verification that the name of a file received by the client matches the file requested. Fixed packages are available with numbers 7.4p1-22.78.amzn1 and 7.4p1-22.amzn2.0.2.

VendorProductVersions

n/a

n/a

affected
n/a

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AC:H/AV:N/A:N/C:N/I:H/PR:N/S:U/UI:R

Attack Complexity

High

Attack Vector

Network

Availability

None

Confidentiality

None

Integrity

High

Privileges Required

None

Scope

Unchanged

User Interaction

Required

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now