CVE-2023-51385
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Ibm Aix, Linuxmint, Apple Macos, Openssh
- Openbsd Openssh
- < 9.6
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 19.8% (97th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2023-12-18
CVE-2023-51385 at NVD
29 known exploits for CVE-2023-51385
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2023-51385
CVE-2023-51385
CVE-2023-51385_test
poc-cve-2023-51385
CVE-2023-51385P-POC
CVE-2023-51385POC
CVE-2023-51385
CVE-2023-51385_test
CVE-2023-51385-exploit
CVE-2023-51385
CVE-2023-51385---OpenSSH-ProxyCommand-Injection-PoC
CVE-2023-51385_test
exploit-CVE-2023-51385
CVE-2023-51385
CVE-2023-51385
malicious-exploit-CVE-2023-51385
CVE-2023-51385-save
CVE-2023-51385_poc
CVE-2023-51385
CVE-2023-51385
CVE-2023-51385_poc-test
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for Race Condition in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh