Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-46595

Опубликовано: 22 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 10

Описание

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

РелизСтатусПримечание
devel

not-affected

0.52.0-1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

released

1:0.47.0-1ubuntu0.1~esm1
esm-infra-legacy/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

ignored

end of life, was needed

Показывать по

РелизСтатусПримечание
devel

not-affected

20250506.01-0ubuntu3
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

released

20250116.00-0ubuntu1~24.04.4
questing

released

20250506.01-0ubuntu1.2
resolute

released

20250506.01-0ubuntu2.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

code-not-present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

questing

ignored

end of life, was needs-triage
resolute

needs-triage

snap

needs-triage

upstream

needs-triage

Показывать по

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

CVSS3: 10
nvd
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

msrc
2 месяца назад

Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

CVSS3: 10
debian
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused s ...

CVSS3: 7.1
redos
20 дней назад

Уязвимость portainer-ce

10 Critical

CVSS3