GHSA-qf84-3fjj-8852MediumCVSS 4.9

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config,...

Published
May 14, 2022
Last Modified
May 28, 2026

🔗 CVE IDs covered (1)

📋 Description

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

🔗 References (25)