OS Command Injection in OpenSSH - CVE-2023-51385
Published: December 26, 2023 / Updated: November 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing user names, if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. A remote attacker can execute arbitrary OS commands via an untrusted Git repository.
Affected software
BIG-IQ Centralized Management
IBM Security Verify Access
Juniper Junos Space
Gentoo Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
F5OS
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
IBM AIX
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
macOS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Oracle Solaris
Red Hat OpenShift Builds
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Security Verify Governance
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Traffix SDC
UCC Edge
Verify Identity Access Digital Credentials
Storage Copy Data Management
PowerStore X
EMC ECS
PowerStore T
Enterprise SONiC
Storage Resource Manager
Dell Policy Manager for Secure Connect Gateway (SCG)
Total Storage Service Console (TSSC) / TS4500 IMC
Storage Protect Plus Container Agent
Storage Protect Plus Server
EMC Cloud Tiering Appliance
IBM VIOS
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssh-server (Ubuntu package)
openssh-client (Ubuntu package)
pam_ssh_agent_auth
openssh-testuser
openssh-debugsource
openssh-fips
openssh-debuginfo
openssh-askpass-gnome-debuginfo
openssh
openssh-helpers
openssh-helpers-debuginfo
openssh-askpass-gnome
openssh (Red Hat package)
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-askpass-gnome-debugsource
openssh-help
openssh (Debian package)
openssh-common-debuginfo
openssh-clients-debuginfo
openssh-server-debuginfo
openssh-common
openssh-cavs-debuginfo
openssh-doc
openssh-sk-dummy
openssh-server-config-disallow-rootlogin
IBM Security Guardium
BIG-IP
BIG-IP Next Central Manager
RSA Authentication Manager
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Dell EMC Storage Monitoring and Reporting (SMR)
OpenShift Data Foundation (formerly OpenShift Container Storage)
RecoverPoint for VMs
IBM Qradar SIEM
AirWave Management Platform
How to mitigate CVE-2023-51385
Red Hat OpenShift Builds - update to 1.0.1
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
UCC Edge - update to 2.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.14.17, 4.15.3
Red Hat Migration Toolkit for Applications - update to 7.0.2
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
macOS - update to 14.4 23E214
openssh-server (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
pam_ssh_agent_auth - addressed in versions 0.10.3-7.20.0.1, 0.10.3-7.20.0.4
pam_ssh_agent_auth - addressed in versions 0.10.3-9.28, 0.10.4-4.23, 0.10.4-4.25
openssh-testuser - update to 0-81.12.1
Red Hat OpenShift GitOps - update to 1.11
Storage Copy Data Management - update to 2.2.23.1
PowerStore X - update to 3.2.1.4-2386214
EMC ECS - update to 3.8.1.1
PowerStore T - update to 4.0.0.2-2365061
Enterprise SONiC - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Dell Secure Connect Gateway - update to 5.24.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
openssh-debugsource - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-fips - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-debuginfo - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-askpass-gnome-debuginfo - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-helpers - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-helpers-debuginfo - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-askpass-gnome - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
openssh (Red Hat package) - addressed in versions 8.0p1-7.el8_4.2, 8.0p1-19.el8_9.2, 8.7p1-13.el9_0.1, 8.7p1-34.el9_3.3
openssh - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-askpass - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-cavs - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4
openssh-clients - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-keycat - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-ldap - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4
openssh-server - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-askpass-gnome-debugsource - addressed in versions 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh - update to 8.2p1-28
openssh-help - update to 8.2p1-28
openssh-keycat - update to 8.2p1-28
openssh-debugsource - update to 8.2p1-28
openssh-askpass - update to 8.2p1-28
openssh-debuginfo - update to 8.2p1-28
openssh-clients - update to 8.2p1-28
openssh-ldap - update to 8.2p1-28
openssh-server - update to 8.2p1-28
openssh-cavs - update to 8.2p1-28
AirWave Management Platform - update to 8.3.0.3
openssh (Debian package) - addressed in versions 1:8.4p1-5+deb11u3, 1:9.2p1-2+deb12u2
openssh-server - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-common-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-clients-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-server-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-cavs - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-common - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-cavs-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-clients - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
RSA Authentication Manager - update to 8.7 SP2 Patch 2
IBM Integrated Analytics System - update to 8.8.24.10.SP1
openssh-doc - update to 9.3p2-6
openssh-sk-dummy - update to 9.3p2-6
Total Storage Service Console (TSSC) / TS4500 IMC - addressed in versions 9.4.26, 9.5.8
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.6.1
IBM Security Verify Governance - update to 10.0.2.0.4
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
Juniper Junos Space - update to 24.1R1 Patch V2
Links to Public Exploits and PoC-codes
External References
- https://www.openssh.com/txt/release-9.6
- https://www.openwall.com/lists/oss-security/2023/12/18/2
- https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1a
- https://www.debian.org/security/2023/dsa-5586
- https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
- http://www.openwall.com/lists/oss-security/2023/12/26/4
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Debian update for openssh
- Gentoo update for OpenSSH
- Ubuntu update for openssh
- Ubuntu update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- SUSE update for openssh
- SUSE update for openssh
- SUSE update for openssh
- OS Command injection in IBM i
- Multiple vulnerabilities in IBM VIOS and IBM AIX
- Multiple vulnerabilities in Apple macOS Sonoma
- openEuler 20.03 LTS SP3 update for openssh
- openEuler 22.03 LTS update for openssh
- openEuler 22.03 LTS SP1 update for openssh
- openEuler 22.03 LTS SP2 update for openssh
- openEuler 20.03 LTS SP1 update for openssh
- Red Hat Enterprise Linux 9 update for openssh
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- openEuler 20.03 LTS SP4 update for openssh
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- SUSE update for openssh
- Multiple vulnerabilities in Dell UCC Edge
- Multiple vulnerabilities in Dell ECS
- Amazon Linux AMI update for openssh
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Total Storage Service Console (TSSC) / TS4500 IMC
- HPE Aruba AirWave Management Platform update for OpenSSH
- Ubuntu update for openssh
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for OpenSSH
- Junos Space update for OpenSSH
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Dell PowerStore X
- OS command injection in F5 BIG-IP OpenSSH component
- OS command injection in F5 BIG-IP Next Central Manager OpenSSH component
- OS command injection in F5 BIG-IQ Centralized Management OpenSSH component
- OS command injection in F5 F5OS OpenSSH component
- OS command injection in F5 Traffix SDC OpenSSH component
- IBM Integrated Analytics System update for OpenSSH
- Multiple vulnerabilities in Dell PowerStore T Family
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Anolis OS update for openssh
- Anolis OS update for openssh
- RSA Authentication Manager update for third-party components
- Anolis OS update for openssh
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- Multiple vulnerabilities in Oracle Solaris
- Red Hat Enterprise Linux 9 update for openssh
- Red Hat Enterprise Linux 8 update for openssh