Is Security affected by CVE-2021-41617?
search cancel

Is Security affected by CVE-2021-41617?

book

Article ID: 264836

calendar_today

Updated On:

Products

Security Analytics Security Analytics - VA

Issue/Introduction

A flaw was found in OpenSSH. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user. Depending on system configuration, inherited groups may allow AuthorizedKeysCommand/AuthorizedPrincipalsCommand helper programs to gain unintended privileges, potentially leading to local privilege escalation.

Resolution

Security Analytics is not affected by CVE-2021-41617.