High severity7.4NVD Advisory· Published Jul 24, 2020· Updated Jun 17, 2026
CVE-2020-15778
CVE-2020-15778
Description
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- OpenSSH/OpenSSHdescription
- osv-coords8 versionspkg:rpm/almalinux/opensshpkg:rpm/almalinux/openssh-askpasspkg:rpm/almalinux/openssh-cavspkg:rpm/almalinux/openssh-clientspkg:rpm/almalinux/openssh-keycatpkg:rpm/almalinux/openssh-ldappkg:rpm/almalinux/openssh-serverpkg:rpm/almalinux/pam_ssh_agent_auth
< 8.0p1-24.el8+ 7 more
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 8.0p1-24.el8
- (no CPE)range: < 0.10.3-7.24.el8
Patches
Vulnerability mechanics
References
5- access.redhat.com/errata/RHSA-2024:3166nvdThird Party Advisory
- news.ycombinator.com/itemnvdThird Party Advisory
- security.gentoo.org/glsa/202212-06nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20200731-0007/nvdThird Party Advisory
- www.openssh.com/security.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.