REDHAT-BUG-2331720: High severity golang/golang.org/x/crypto/ssh vulnerability
Published Dec 11, 2024
·Updated
Applications and libraries which misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass.
Affected Software
1 affected component
golang/golang.org/x/crypto/ssh
Event History
Dec 11, 2024
Data Sourced
via Red Hat·07:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2331720?
The severity of REDHAT-BUG-2331720 is high with a score of 7.
2
What does REDHAT-BUG-2331720 entail?
REDHAT-BUG-2331720 involves applications and libraries misusing the ServerConfig.PublicKeyCallback callback, which may lead to an authorization bypass.
3
How do I fix REDHAT-BUG-2331720?
To fix REDHAT-BUG-2331720, ensure proper implementation and validation of the ServerConfig.PublicKeyCallback in your applications and libraries.
4
Which software is affected by REDHAT-BUG-2331720?
The software affected by REDHAT-BUG-2331720 includes golang/golang.org/x/crypto/ssh.
5
What are the risks of not addressing REDHAT-BUG-2331720?
Failing to address REDHAT-BUG-2331720 could result in unauthorized access and severe security vulnerabilities within your applications.