Impact
A malformed line‑anchor rule in btrbk's ssh_filter_btrbk.sh allows an attacker to bypass the command allowlist and execute arbitrary commands through a forced‑command entry in authorized_keys. The flaw is an instance of OS command injection (CWE‑78) and lets the attacker run any instruction with the SSH account's privileges used for backups, potentially giving full control over the backup target system.
Affected Systems
The vulnerability affects users of Digint btrbk versions 0.29.0 through 0.32.6 that deploy ssh_filter_btrbk.sh as a forced command in authorized_keys. Deployments that do not use the script in authorized_keys, or that are running a later version (0.32.7 or newer), are not impacted.
Risk and Exploitability
With a CVSS score of 8.7 and an EPSS score of < 1%, the risk is considered high. The flaw can be triggered through a normal SSH forced‑command entry, so any attacker who can influence authorized_keys on the backup target can exploit it. The vulnerability is not listed in CISA's KEV catalog, but its severity and vector warrant close attention and timely remediation.
OpenCVE Enrichment