View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2018-10933 severity critical: SUSE including 286 source package names (14.28:libssh4-0.6.3-12.6.1, 15.0:libssh4-0.7.5-6.3.1, …), 387 product×package rows across 59 product lines (Container suse/sle15, Container suse/sles12sp4, … (59 product lines)): Known Affected 157, Fixed 156, Known Not Affected 74.
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.