scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "8.3"
},
{
"introduced": "0"
},
{
"last_affected": "8.3-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.3-p1"
}
]
}