You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Potentially version is vulnerable to remote code execution as per CVE-2024-6387
Add-on version: 17.3.0
You are running the latest version of this add-on.
System: Debian GNU/Linux 12 (bookworm) (aarch64 / qemuarm-64)
Home Assistant Core: 2024.7.1
Home Assistant Supervisor: 2024.06.2
➜ ~ ssh -V
OpenSSH_9.6p1, OpenSSL 3.1.4 24 Oct 2023
Currently used ssh version looks updated already, but the addon (18) is not yet released (17.3.0 is reported as latest in HA).
Both latest released and latest unreleased ssh version may be vulnerable:
The vulnerability resurfaces in versions from 8.5p1 up to, but not including, 9.8p1 due to the accidental removal of a critical component in a function.
Problem/Motivation
Potentially version is vulnerable to remote code execution as per CVE-2024-6387
Related to:
addon-ssh/ssh/Dockerfile
Line 59 in 7fd5170
Currently used ssh version looks updated already, but the addon (18) is not yet released (17.3.0 is reported as latest in HA).
Both latest released and latest unreleased ssh version may be vulnerable:
Source
Expected behavior
We need an assurance that SSH Addon does not ship a vulnerable version of openssh (remote code execution).
Proposed changes
Update openssh package to the latest version.
The text was updated successfully, but these errors were encountered: