OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
| Vendor | Product | Versions |
|---|---|---|
| openssh | openssh | 0, < 10.3 |
Updated affected versions to include 10.2, changed severity to HIGH, and noted that the vulnerability is actively exploited.
Initial creation