Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-28531

Description

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

POC

Reference

No PoCs from references.

Github

- https://github.com/Certifiedhustler-Swaba/VulnerableGPT

- https://github.com/GitHubForSnap/openssh-server-gael

- https://github.com/Raj-h-hacker/GPT_Vuln-analyzer

- https://github.com/SourcePointSecurity/SwampScan

- https://github.com/Spyr026/Proyecto-Ciberseguridad

- https://github.com/akashkannancybersec/Echothreat

- https://github.com/alvarigno22/NodeClimb-DockerLab

- https://github.com/blessing-gao/SecurityPatcher

- https://github.com/byfranke/Estudo_de_Casos_HdB

- https://github.com/drg3nz0/gpt-analyzer

- https://github.com/fkie-cad/nvd-json-data-feeds

- https://github.com/morpheuslord/GPT_Vuln-analyzer

- https://github.com/nzelyn/GPT_Vuln-analyzer

- https://github.com/testing-felickz/docker-scout-demo