7

CVE-2021-41617

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbsd ≫ Openssh Version >= 6.2 < 8.8
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Aff A250 Firmware Version -
   Netapp ≫ Aff A250 Version -
Netapp ≫ Aff 500f Firmware Version -
   Netapp ≫ Aff 500f Version -
Oracle ≫ HTTP Server Version 12.2.1.2.0
Oracle ≫ HTTP Server Version 12.2.1.3.0
Oracle ≫ HTTP Server Version 12.2.1.4.0
Starwindsoftware ≫ Starwind Virtual San Version v8r13 Update 14398
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.55% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
https://www.openssh.com/security.html
Vendor Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1190975
Patch
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
https://security.netapp.com/advisory/ntap-20211014-0004/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5586
https://www.openssh.com/txt/release-8.8
Vendor Advisory
Release Notes
https://www.openwall.com/lists/oss-security/2021/09/26/1
Third Party Advisory
Mailing List
https://www.starwindsoftware.com/security/sw-20220805-0001/
Third Party Advisory
https://www.tenable.com/plugins/nessus/154174
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/
https://cert-portal.siemens.com/productcert/html/ssa-019113.html