Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 34

Количество 34

ubuntu логотип

CVE-2024-45337

больше 1 года назад

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b...

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2024-45337

больше 1 года назад

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b...

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2024-45337

больше 1 года назад

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be c

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2024-45337

больше 1 года назад

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2024-45337

больше 1 года назад

Applications and libraries which misuse connection.serverAuthenticate ...

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0025-1

больше 1 года назад

Security update for cheat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1143-1

больше 1 года назад

Security update for google-guest-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1142-1

больше 1 года назад

Security update for google-guest-agent

EPSS: Низкий
github логотип

GHSA-v778-237x-gjrc

больше 1 года назад

Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2024-11338

больше 1 года назад

Уязвимость функции ServerConfig.PublicKeyCallback() библиотеки для языка программирования Go crypto, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20609-1

3 месяца назад

Security update for google-guest-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0602-1

больше 1 года назад

Security update for helm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0601-1

больше 1 года назад

Security update for brise

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02581-1

около 1 года назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

EPSS: Низкий
redos логотип

ROS-20250110-14

больше 1 года назад

Уязвимость gitea

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20241220-04

больше 1 года назад

Уязвимость golang-x-crypto-devel

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0094-1

больше 1 года назад

Security update for gitea-tea

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03278-1

11 месяцев назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20893-1

2 месяца назад

Security update for cloudflared

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0545-1

больше 1 года назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-45337

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b...

CVSS3: 9.1
3%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-45337

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would b...

CVSS3: 8.2
3%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45337

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be c

CVSS3: 9.1
3%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-45337

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

CVSS3: 9.1
3%
Низкий
больше 1 года назад
debian логотип
CVE-2024-45337

Applications and libraries which misuse connection.serverAuthenticate ...

CVSS3: 9.1
3%
Низкий
больше 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:0025-1

Security update for cheat

3%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1143-1

Security update for google-guest-agent

3%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1142-1

Security update for google-guest-agent

3%
Низкий
больше 1 года назад
github логотип
GHSA-v778-237x-gjrc

Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

CVSS3: 9.1
3%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-11338

Уязвимость функции ServerConfig.PublicKeyCallback() библиотеки для языка программирования Go crypto, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 9.1
3%
Низкий
больше 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:20609-1

Security update for google-guest-agent

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0602-1

Security update for helm

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0601-1

Security update for brise

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02581-1

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

около 1 года назад
redos логотип
ROS-20250110-14

Уязвимость gitea

CVSS3: 9.1
3%
Низкий
больше 1 года назад
redos логотип
ROS-20241220-04

Уязвимость golang-x-crypto-devel

CVSS3: 9.1
3%
Низкий
больше 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:0094-1

Security update for gitea-tea

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:03278-1

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

11 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20893-1

Security update for cloudflared

2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:0545-1

Security update for grafana

больше 1 года назад

Уязвимостей на страницу