CVE-2023-6004 is a medium-severity vulnerability in libssh, affecting various Fedora and Red Hat Enterprise Linux products. It allows for malicious code injection via unchecked hostname syntax when using ProxyCommand or ProxyJump features. The attack requires local access and user interaction, potentially leading to low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion beyond a single media mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.8.0, < 0.9.8CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
>= 0.10.0, < 0.10.6CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname
Jan 9, 2024libssh: ProxyCommand/ProxyJump features allow injection of malicious code through hostname
Dec 18, 2023