Public-Key Authentication Vulnerability in OpenSSH by OpenBSD
CVE-2021-36368
3.7LOW
What is CVE-2021-36368?
A vulnerability exists in OpenSSH prior to version 8.9, where a client using public-key authentication with agent forwarding could be at risk if the server has been silently modified to support the None authentication option. This can create confusion for users, as they cannot easily determine whether the FIDO authentication is genuinely confirming their intent to connect to the server or if it's granting permission for the server to connect to another server on their behalf. This situation emphasizes the importance of monitoring server configurations and considering the implications of agent forwarding in secure communications.