ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
2023-03-17T04:15:14.553
2024-11-21T07:55:17.627
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openbsd | openssh | < 9.3 | Yes |
Operating System | netapp | brocade_fabric_operating_system | - | Yes |
Operating System | netapp | hci_bootstrap_os | - | Yes |
Operating System | netapp | solidfire_element_os | - | Yes |