cpandya2909/CVE-2020-15778

cpandya2909/CVE-2020-15778

Releases0
Stars145

CVE History

CVEPublishedCVSS v3CVSS v2
7.4 HIGH6.8 MEDIUM

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."