Back to search
CVE-2023-51385
Published: Dec 18, 2023
Modified: May 12, 2026
PUBLISHED
Description
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-5586
vendor-advisory
GLSA-202312-17
vendor-advisory
20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4
mailing-list
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now