CVE-2023-6004

A

flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

04 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/ -

21 Nov 2024, 08:42

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/ -
  • () https://security.netapp.com/advisory/ntap-20240223-0004/ -
References () https://access.redhat.com/errata/RHSA-2024:2504 - () https://access.redhat.com/errata/RHSA-2024:2504 -
References () https://access.redhat.com/errata/RHSA-2024:3233 - () https://access.redhat.com/errata/RHSA-2024:3233 -
References () https://access.redhat.com/security/cve/CVE-2023-6004 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-6004 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2251110 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2251110 - Issue Tracking
References () https://www.libssh.org/security/advisories/CVE-2023-6004.txt - Mailing List () https://www.libssh.org/security/advisories/CVE-2023-6004.txt - Mailing List

16 Sep 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/[email protected]/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/', 'tags': ['Mailing List', 'Vendor Advisory'], 'source': '[email protected]'}
  • {'url': 'https://security.netapp.com/advisory/ntap-20240223-0004/', 'source': '[email protected]'}

22 May 2024, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3233 -

30 Apr 2024, 15:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2504 -

Information

Published : 2024-01-03 17:15

Updated : 2025-11-04 19:16


NVD link : CVE-2023-6004

Mitre link : CVE-2023-6004

CVE.ORG link : CVE-2023-6004


JSON object : View

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')