Improper authorization control for web services In openssh
Description
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | >=0 <1:9.3p1-1 | 1:9.3p1-1 | |
alpine v3.16 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || >=0 <9.0_p1-r3 | 9.0_p1-r3 | |
alpine v3.17 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || =9.0_p1-r3 || =9.0_p1-r4 || =9.1_p1-r0 || =9.1_p1-r1 || =9.1_p1-r2 || >=0 <9.1_p1-r3 | 9.1_p1-r3 | |
debian 12 | =1:9.2p1-2 || =1:9.2p1-2+deb12u1 || >=0 <1:9.2p1-2+deb12u2 | 1:9.2p1-2+deb12u2 | |
debian 14 | >=0 <1:9.3p1-1 | 1:9.3p1-1 |
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.