VDB
Sign up
HIGH8.1

GHSA-xhjq-w7xm-p8qj

golang.org/x/crypto/ssh Man-in-the-Middle attack

Quick fix

GHSA-xhjq-w7xm-p8qj — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.0.0-20170330155735-e4e2799dd7aa

Details

The Go SSH library (golang.org/x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks if ClientConfig.HostKeyCallback is not set. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.0.0-20170330155735-e4e2799dd7aa
Fixgo get golang.org/x/crypto@v0.0.0-20170330155735-e4e2799dd7aa

References