CVE Vulnerabilities

CVE-2023-51384

Published: Dec 18, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

Affected Software

NameVendorStart VersionEnd Version
OpensshOpenbsd8.9 (including)9.6 (excluding)
OpensshUbuntubionic*
OpensshUbuntudevel*
OpensshUbuntufips-preview/jammy*
OpensshUbuntufips-updates/jammy*
OpensshUbuntujammy*
OpensshUbuntulunar*
OpensshUbuntumantic*
OpensshUbuntunoble*
OpensshUbuntuoracular*
OpensshUbuntutrusty*
OpensshUbuntuupstream*
OpensshUbuntuxenial*
Openssh-ssh1Ubuntubionic*
Openssh-ssh1Ubuntudevel*
Openssh-ssh1Ubuntuesm-apps/bionic*
Openssh-ssh1Ubuntuesm-apps/focal*
Openssh-ssh1Ubuntuesm-apps/jammy*
Openssh-ssh1Ubuntuesm-apps/noble*
Openssh-ssh1Ubuntufocal*
Openssh-ssh1Ubuntujammy*
Openssh-ssh1Ubuntulunar*
Openssh-ssh1Ubuntumantic*
Openssh-ssh1Ubuntunoble*
Openssh-ssh1Ubuntuoracular*
Openssh-ssh1Ubuntuupstream*

References