Improper Neutralization of Special Elements used in a Command ('Command Injection') Affecting libssh package, versions [,0.9.8)[0.10.0,0.10.6)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.45% (36th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBSSH-6132397
  • published20 Dec 2023
  • disclosed18 Dec 2023
  • creditVinci

Introduced: 18 Dec 2023

CVE-2023-6004  (opens in a new tab)
CWE-77  (opens in a new tab)

How to fix?

Upgrade libssh to version 0.9.8, 0.10.6 or higher.

Overview

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') via the ProxyCommand/ProxyJump features. An attacker can inject malicious code through the hostname.

CVSS Base Scores

version 3.1