The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=109413637313484&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17213 | vdb entry |
http://securitytracker.com/id?1011143 | vdb entry |
http://www.osvdb.org/9562 | vdb entry |
https://security.netapp.com/advisory/ntap-20191107-0001/ |