Количество 34
Количество 34
BDU:2024-11338
Уязвимость функции ServerConfig.PublicKeyCallback() библиотеки для языка программирования Go crypto, позволяющая нарушителю обойти ограничения безопасности
ROS-20250110-14
Уязвимость gitea
ROS-20241220-04
Уязвимость golang-x-crypto-devel
ROS-20250219-03
Множественные уязвимости trivy
ROS-20251203-11
Множественные уязвимости etcd
ROS-20251203-10
Множественные уязвимости etcd
CVE-2024-45337
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b...
CVE-2024-45337
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b...
CVE-2024-45337
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be c
CVE-2024-45337
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
CVE-2024-45337
Applications and libraries which misuse connection.serverAuthenticate ...
openSUSE-SU-2025:0025-1
Security update for cheat
SUSE-SU-2025:1143-1
Security update for google-guest-agent
SUSE-SU-2025:1142-1
Security update for google-guest-agent
GHSA-v778-237x-gjrc
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
openSUSE-SU-2026:20609-1
Security update for google-guest-agent
SUSE-SU-2025:0602-1
Security update for helm
SUSE-SU-2025:0601-1
Security update for brise
SUSE-SU-2025:02581-1
Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container
openSUSE-SU-2025:0094-1
Security update for gitea-tea
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-11338 Уязвимость функции ServerConfig.PublicKeyCallback() библиотеки для языка программирования Go crypto, позволяющая нарушителю обойти ограничения безопасности | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
ROS-20250110-14 Уязвимость gitea | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
ROS-20241220-04 Уязвимость golang-x-crypto-devel | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
ROS-20250219-03 Множественные уязвимости trivy | CVSS3: 9.8 | больше 1 года назад | ||
ROS-20251203-11 Множественные уязвимости etcd | CVSS3: 9.1 | 8 месяцев назад | ||
ROS-20251203-10 Множественные уязвимости etcd | CVSS3: 9.1 | 8 месяцев назад | ||
CVE-2024-45337 Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b... | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
CVE-2024-45337 Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b... | CVSS3: 8.2 | 3% Низкий | больше 1 года назад | |
CVE-2024-45337 Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be c | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
CVE-2024-45337 Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
CVE-2024-45337 Applications and libraries which misuse connection.serverAuthenticate ... | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
openSUSE-SU-2025:0025-1 Security update for cheat | 3% Низкий | больше 1 года назад | ||
SUSE-SU-2025:1143-1 Security update for google-guest-agent | 3% Низкий | больше 1 года назад | ||
SUSE-SU-2025:1142-1 Security update for google-guest-agent | 3% Низкий | больше 1 года назад | ||
GHSA-v778-237x-gjrc Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto | CVSS3: 9.1 | 3% Низкий | больше 1 года назад | |
openSUSE-SU-2026:20609-1 Security update for google-guest-agent | 3 месяца назад | |||
SUSE-SU-2025:0602-1 Security update for helm | больше 1 года назад | |||
SUSE-SU-2025:0601-1 Security update for brise | больше 1 года назад | |||
SUSE-SU-2025:02581-1 Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container | около 1 года назад | |||
openSUSE-SU-2025:0094-1 Security update for gitea-tea | больше 1 года назад |
Уязвимостей на страницу