—
GO-2024-2836
sshproxy vulnerable to SSH option injection in github.com/cea-hpc/sshproxy
Quick fix
GO-2024-2836 — github.com/cea-hpc/sshproxy: upgrade to the fixed version with the command below.
go get github.com/cea-hpc/sshproxy@v1.6.3Details
sshproxy vulnerable to SSH option injection in github.com/cea-hpc/sshproxy
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/cea-hpc/sshproxy
Introduced in:
0Fixed in: 1.6.3Fix
go get github.com/cea-hpc/sshproxy@v1.6.3References
- https://github.com/cea-hpc/sshproxy/security/advisories/GHSA-jmqp-37m5-49wh[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-34713[ADVISORY]
- https://github.com/cea-hpc/sshproxy/commit/3b8bccc874dc4ca2c80c956cad65722abb46f0b9[FIX]
- https://github.com/cea-hpc/sshproxy/commit/f7eabd05d5f0f951e160293692327cad9a7d9580[FIX]