Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:16908
HistoryMay 02, 2019 - 5:29 a.m.

Authentication Bypass

2019-05-0205:29:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.004 Low

EPSS

Percentile

72.5%

openssh is vulnerable to authentication bypass. The OpenSSH client did not correctly handle failures to generate authentication cookies for untrusted X11 forwarding. A malicious or compromised remote X application could possibly use this flaw to establish a trusted connection to the local X server, even if only untrusted X11 forwarding was requested.

References