{"id":"CGA-jvq7-32rc-8m88","modified":"2026-07-17T19:08:14.018719270Z","published":"2025-10-30T20:06:10Z","upstream":["CVE-2023-38408","GHSA-px36-p9hv-7h2v"],"references":[{"type":"WEB","url":"https://support.apple.com/kb/HT213940"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/exploring-opensshs-agent-forwarding-rce-cve-2023-38408"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230803-0010/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202307-01"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/f03a4faa55c4ce0818324701dadbf91988d7351d"},{"type":"WEB","url":"http://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execution.html"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=36790196"},{"type":"WEB","url":"https://www.openssh.com/security.html"},{"type":"WEB","url":"https://www.openssh.com/txt/release-9.3p2"},{"type":"WEB","url":"https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38408.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CEBTJJINE2I3FHAUKKNQWMFGYMLSMWKQ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAXVQS6ZYTULFAK3TEJHRLKZALJS3AOU/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38408"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/07/20/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/07/20/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/09/22/11"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/09/22/9"},{"type":"ARTICLE","url":"https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00021.html"}],"affected":[{"package":{"name":"openssh","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/openssh?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3_p2-r0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:apk/openssh","latest_event_status":"fixed","latest_event_timestamp":"2023-07-19T16:06:22Z","architecture":"x86_64","component_name":"openssh","component_version":"","component_type":"apk","component_location":"/.PKGINFO"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-jvq7-32rc-8m88.json"}},{"package":{"name":"openssh","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/openssh?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3_p2-r0"}]}],"ecosystem_specific":{"components":[{"component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/openssh","latest_event_status":"fixed","latest_event_timestamp":"2023-07-19T16:06:22Z","architecture":"x86_64","component_name":"openssh","component_version":""}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-jvq7-32rc-8m88.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}