VDB
Sign up
MEDIUM6.3

GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

Quick fix

GHSA-45gg-vh54-h5m9 — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.52.0

Details

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.52.0
Fixgo get golang.org/x/crypto@v0.52.0

References