
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2023-6004 is a security vulnerability discovered in libssh, affecting versions 0.8.0 prior to 0.9.8 and 0.10.0 prior to 0.10.6. The vulnerability was disclosed on January 3, 2024, and involves unchecked hostname syntax in the ProxyCommand or ProxyJump features on the client side (LibSSH Advisory).
The vulnerability exists in libssh's implementation of ProxyCommand and ProxyJump features, where unchecked hostname syntax on the client side can be exploited. The issue has a CVSS v3.1 base score of 4.8 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L, indicating local access is required and user interaction is necessary for exploitation (NVD, Red Hat).
When successfully exploited, this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The attack requires user interaction and local access to be effective (NetApp Advisory).
The primary mitigation is to upgrade to libssh versions 0.9.8 or 0.10.6 or later, which contain the security fixes. For systems that cannot be immediately updated, the recommended workaround is to sanitize hostname input (LibSSH Advisory). Multiple vendors have released security updates to address this vulnerability, including Red Hat through RHSA-2024:2504 and RHSA-2024:3233 (Red Hat Errata).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”