Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:16746
HistoryMay 02, 2019 - 5:27 a.m.

CRLF Injection

2019-05-0205:27:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.023

Percentile

89.8%

OpenSSH is vulnerable to CRLF injection. It was discovered that the OpenSSH server did not sanitize data received in requests to enable X11 forwarding. An authenticated client with restricted SSH access could possibly use this flaw to bypass intended restrictions.

References