Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-6387-Mitigation-Ansible-Playbook — An Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version. | Kitploit
Tools/GitHubGitHub/daniel-odrinski/cve-2024-6387-mitigation-ansible-playbook
Cloud Infrastructure SecurityVulnerability ScannersConfiguration AuditingDevSecOpsIncident Response
GitHubdaniel-odrinski/cve-2024-6387-mitigation-ansible-playbook

CVE-2024-6387-Mitigation-Ansible-Playbook

An Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
52 years agoNot yet reviewed
Share

CVE-2024-6387 Mitigation Ansible Playbook

An Ansible Playbook to mitigate the risk of the regreSSHion RCE (CVE-2024-6387) vulnerability until platforms update OpenSSH to a non-vulnerable version.

The mitigation applied here is based on the Mitigation Advice provided by Red Hat. As noted there:

Notice the sshd server will still be vulnerable to Denial of Service attacks due to there possibility os MaxStartups connection exhaustion, however it'll be safe against possible remote code execution attacks.

You should keep this in mind before applying the mitigation.

Pre-requisites

  • Ansible
  • Linux server with OpenSSH Server installed

Assumptions

  • You have a drop-in configuration directory at: /etc/ssh/sshd_config.d/
  • You are affected by CVE-2024-6387 - see affected package versions here.
  • ansible user set up on target server(s) with sufficient permissions to write in /etc/ssh/sshd_config.d/. Here, sudo permissions are assumed for best compatibility (though this is not necessarily the best approach).

The playbook also includes an alternative step (to replace the drop-in one) which could be used to apply this patch in-place i.e. in the /etc/ssh/sshd_config file itself.

Usage

root@kitploit:~
ansible-playbook ./apply_mitigation.yaml --limit <your host group>

Disclaimer

This Ansible playbook is provided AS IS WITHOUT WARRANTY and WITHOUT ANY LIABILITY. If you break your SSHd configuration, servers or anything else, I take no responsibility.

Just sharing this to help others.

Download Tool