Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x527-x647-q7gg

Опубликовано: 25 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 10

Описание

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

Пакеты

Наименование

golang.org/x/crypto

go
Затронутые версииВерсия исправления

< 0.52.0

0.52.0

EPSS

Процентиль: 40%
0.00503
Низкий

10 Critical

CVSS3

Дефекты

CWE-303
CWE-863

Связанные уязвимости

CVSS3: 10
ubuntu
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

CVSS3: 7.1
redhat
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

CVSS3: 10
nvd
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

msrc
2 месяца назад

Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

CVSS3: 10
debian
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused s ...

EPSS

Процентиль: 40%
0.00503
Низкий

10 Critical

CVSS3

Дефекты

CWE-303
CWE-863