Bug 2331720 (CVE-2024-45337)
Summary: | CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | ahanwate, alcohan, amctagga, anjoseph, aoconnor, bdettelb, bkabrda, bniver, crizzo, danken, dhanak, doconnor, dsimansk, dymurray, eglynn, fdeutsch, flucifre, gkamathe, gmeno, gparvin, jaharrin, jburrell, jeder, jforrest, jjoyce, jkoehler, jmatthew, jprabhak, jschluet, jwendell, kingland, kverlaen, lball, lhh, lphiri, lsvaty, manissin, matzew, mbenjamin, mburns, mgarciac, mhackett, mnovotny, ngough, njean, nobody, oramraz, owatkins, padillon, pahickey, pgrist, phoracek, pierdipi, rcernich, rguimara, rhaigner, rhos-maint, rhuss, rjohnson, sausingh, sdawley, smullick, sostapov, stirabos, teagle, thason, twalsh, vereddy, veshanka, whayutin, wtam |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | Flags: | phoracek:
needinfo?
(ahanwate) |
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | v0.31.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2331920, 2331921, 2331922, 2331923, 2331924, 2331925, 2331928, 2331929, 2331930, 2331931, 2331932, 2331935, 2331936, 2331938, 2331966, 2331967, 2331968, 2331972, 2331973, 2331974, 2331975, 2331977, 2331978, 2331979, 2331985, 2331986, 2331990, 2331917, 2331919, 2331926, 2331927, 2331933, 2331934, 2331937, 2331939, 2331940, 2331941, 2331942, 2331943, 2331944, 2331945, 2331946, 2331947, 2331948, 2331949, 2331950, 2331951, 2331952, 2331953, 2331954, 2331955, 2331956, 2331957, 2331958, 2331959, 2331960, 2331961, 2331962, 2331963, 2331964, 2331965, 2331969, 2331970, 2331971, 2331976, 2331980, 2331981, 2331982, 2331983, 2331984, 2331987, 2331988, 2331989, 2331991, 2332003, 2332004, 2332005, 2332006, 2332007, 2332008, 2332009, 2332010, 2332012, 2332013, 2350499 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2024-12-11 19:01:18 UTC
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:0385 https://access.redhat.com/errata/RHSA-2025:0385 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0386 https://access.redhat.com/errata/RHSA-2025:0386 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.4 for RHEL 8 Via RHSA-2025:0552 https://access.redhat.com/errata/RHSA-2025:0552 This issue has been addressed in the following products: multicluster-globalhub 1.2 for RHEL 9 Via RHSA-2025:0560 https://access.redhat.com/errata/RHSA-2025:0560 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 Via RHSA-2025:0576 https://access.redhat.com/errata/RHSA-2025:0576 This issue has been addressed in the following products: multicluster-globalhub 1.3 for RHEL 9 Via RHSA-2025:0577 https://access.redhat.com/errata/RHSA-2025:0577 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.5 for RHEL 9 multicluster engine for Kubernetes 2.5 for RHEL 8 Via RHSA-2025:0676 https://access.redhat.com/errata/RHSA-2025:0676 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 Via RHSA-2025:0679 https://access.redhat.com/errata/RHSA-2025:0679 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.7 for RHEL 9 multicluster engine for Kubernetes 2.7 for RHEL 8 Via RHSA-2025:0723 https://access.redhat.com/errata/RHSA-2025:0723 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0653 https://access.redhat.com/errata/RHSA-2025:0653 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.6 for RHEL 9 multicluster engine for Kubernetes 2.6 for RHEL 8 Via RHSA-2025:0778 https://access.redhat.com/errata/RHSA-2025:0778 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0785 https://access.redhat.com/errata/RHSA-2025:0785 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:0649 https://access.redhat.com/errata/RHSA-2025:0649 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:0645 https://access.redhat.com/errata/RHSA-2025:0645 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:0851 https://access.redhat.com/errata/RHSA-2025:0851 This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2025:0892 https://access.redhat.com/errata/RHSA-2025:0892 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:0839 https://access.redhat.com/errata/RHSA-2025:0839 This issue has been addressed in the following products: gatekeeper 3.17 for RHEL 9 Via RHSA-2025:1331 https://access.redhat.com/errata/RHSA-2025:1331 This issue has been addressed in the following products: gatekeeper 3.15 for RHEL 9 Via RHSA-2025:1332 https://access.redhat.com/errata/RHSA-2025:1332 This issue has been addressed in the following products: gatekeeper 3.14 for RHEL 9 Via RHSA-2025:1333 https://access.redhat.com/errata/RHSA-2025:1333 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.5 Via RHSA-2025:1334 https://access.redhat.com/errata/RHSA-2025:1334 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.4 Via RHSA-2025:1468 https://access.redhat.com/errata/RHSA-2025:1468 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:1451 https://access.redhat.com/errata/RHSA-2025:1451 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2024:6121 https://access.redhat.com/errata/RHSA-2024:6121 This issue has been addressed in the following products: RHODF-4.17-RHEL-9 Via RHSA-2025:1824 https://access.redhat.com/errata/RHSA-2025:1824 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:1829 https://access.redhat.com/errata/RHSA-2025:1829 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:1710 https://access.redhat.com/errata/RHSA-2025:1710 This issue has been addressed in the following products: RHODF-4.18-RHEL-9 Via RHSA-2025:2652 https://access.redhat.com/errata/RHSA-2025:2652 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.14 Via RHSA-2025:3069 https://access.redhat.com/errata/RHSA-2025:3069 This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:3542 https://access.redhat.com/errata/RHSA-2025:3542 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:3560 https://access.redhat.com/errata/RHSA-2025:3560 This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2025:8244 https://access.redhat.com/errata/RHSA-2025:8244 |