CVE-2023-51385

The OpenSSH ProxyCommand injection: a shell metacharacter in a host name, expanded into a command

A client-side flaw, and the interesting cases are all automation. If anything on your server runs ssh with a host name or user name it did not choose, this is the bug that turns that into command execution.

OpenSSHNot in CISA’s Known Exploited catalogueEPSS 19.8% chance of an attempt in 30 daysCVSS 6.5CWE-78CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

A fixed package version is available on 5 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

The ssh client expands tokens such as %h and %u into a ProxyCommand before handing it to a shell. A host name containing shell metacharacters is expanded verbatim, so the shell runs whatever was hidden in it.

What an attacker gets: Command execution as the user running ssh, on the machine running ssh. Not on the server being connected to.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It needs a ProxyCommand (or a ProxyJump, which becomes one) configured with a token.
  • The host or user name has to come from somewhere the attacker influences. A hand-typed hostname is not a risk; a submodule URL, a CI variable or a hostname read from a database is.
  • Git repositories with submodules were the widely discussed route, because a repository can name the host a clone connects to.

Check your own server

Read-only, changes nothing
grep -rniE '^\s*(ProxyCommand|ProxyJump)' /etc/ssh/ssh_config /etc/ssh/ssh_config.d/ ~/.ssh/config 2>/dev/null

No ProxyCommand and no ProxyJump anywhere means nothing on this machine takes the affected path.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSopensshFixed1:8.9p1-3ubuntu0.6
Ubuntu 24.04 LTSopensshFixed1:9.6p1-3ubuntu1
Debian 12 (bookworm)opensshFixed1:9.2p1-2+deb12u2
Debian 13 (trixie)opensshFixed1:9.6p1-1
Rocky Linux 9opensshNo advisory names itno advisory for this release names it
AlmaLinux 9opensshFixed8.7p1-34.el9_3.3

Install the fix with apt update && apt install --only-upgrade openssh-server openssh-client on Debian and Ubuntu, or dnf update openssh-server openssh-clients on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.

Recorded from nvd. Its weakness class is CWE-78, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-51385 included. It changes nothing.