Impact
The vulnerability in libssh allows a maliciously crafted username to be expanded through the %r placeholder in ProxyCommand processing, enabling the injection of shell metacharacters. This flaw can lead to the disclosure of environment variables and unintended shell behavior, effectively exposing sensitive configuration data that may be available to an attacker who can supply or influence the username value. The weakness corresponds to improper input validation and is classified as an information exposure issue.
Affected Systems
Red Hats Red Enterprise Linux distributions—including versions 8, 9, 10—and the Red Hats Hardened Images rely on libssh. The advisory does not list specific libssh versions, so any installation containing libssh on the affected distributions may be vulnerable.
Risk and Exploitability
The CVSS score of 3.9 indicates a low severity impact focused on confidentiality. The EPSS score of less than 1% suggests that exploitation attempts are unlikely in current threat data, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring an attacker to initiate an SSH connection using a ProxyCommand that expands %r; thus the user must control or influence the username submitted to the SSH daemon. Given the low exploitation likelihood and limited information leakage, the overall risk remains moderate, but the vulnerability should still be addressed promptly to avoid inadvertent data exposure.
OpenCVE Enrichment
Debian DSA