First published: Thu Apr 10 2025(Updated: )
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH server | <10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32728 has been assessed as a moderate severity vulnerability due to its potential impact on secure remote session forwarding.
To fix CVE-2025-32728, you should upgrade OpenSSH to version 10.0 or later where the DisableForwarding directive functions as documented.
The consequences of CVE-2025-32728 include the unintended allowance of X11 and agent forwarding, which could lead to security breaches.
CVE-2025-32728 affects OpenSSH versions prior to 10.0, specifically affecting the sshd component.
A workaround for CVE-2025-32728 is to manually configure the forwarding settings in your SSH configuration until an upgrade can be applied.