scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*"
],
"vendor_product": "netapp:active_iq_unified_manager",
"extracted_events": [
{
"introduced": "9.5"
}
]
}
]
}{
"cpe": [
"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:8.3:-:*:*:*:*:*:*",
"cpe:2.3:a:openbsd:openssh:8.3:p1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.3"
},
{
"introduced": "8.3-NA"
},
{
"last_affected": "8.3-NA"
},
{
"introduced": "8.3-p1"
},
{
"last_affected": "8.3-p1"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}