Incomplete Destination Constraints in OpenSSH Affecting Key Management
CVE-2023-51384
5.5MEDIUM
Key Information:
Badges
đź“° News Worthy
What is CVE-2023-51384?
In OpenSSH versions prior to 9.6, a vulnerability exists within the ssh-agent related to the handling of destination constraints during the addition of PKCS#11-hosted private keys. The issue arises when these constraints are specified; they are only applied to the first added key, leading to potential security risks if multiple keys reside on the PKCS#11 token. This incomplete enforcement of constraints emphasizes the need for users to review their key management processes and update to the latest version of OpenSSH to mitigate associated risks.