← Back to CVE List

CVE-2023-51385

Published: 2023-12-18T19:15Z
Last Modified: 2024-11-21T08:37Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt