The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
https://security.netapp.com/advisory/ntap-20191107-0001/
https://exchange.xforce.ibmcloud.com/vulnerabilities/17213