← Back

CVE-2021-41617

nvd nist
Published: Sep 26, 2021Modified: Jul 14, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

Affected (16)

Show all products
1 product
Openssh
1 product
Fedora
7 products
Active Iq Unified Manager
Clustered Data Ontap
Hci Management Node
Solidfire
Aff A250 Firmware
Aff 500f Firmware
2 products
Http Server
Zfs Storage Appliance Kit
Starwind Virtual San
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.2 to 8.8
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Version 35
Configuration C
5 vulnerable
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Aff A250
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Aff 500f
All versions
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.2.1.2.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 8.8
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version v8r13 14398

References (30)

Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.