openbsd openssh CVE-2021-36368 vulnerability in OpenBSD and Other Products
Published on March 13, 2022

product logo product logo product logo
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.

NVD


Products Associated with CVE-2021-36368

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-36368 are published in these products:

 
 
 

Exploit Probability

EPSS
0.40%
Percentile
59.94%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.