VDB
Sign up
CRITICAL10.0

GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

Quick fix

GHSA-x527-x647-q7gg — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.52.0

Details

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.52.0
Fixgo get golang.org/x/crypto@v0.52.0

References