Bug 2331720 (CVE-2024-45337)
| Summary: | CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | ahanwate, alcohan, amctagga, anjoseph, aoconnor, aruklets, bdettelb, bniver, crizzo, danken, dhanak, dkeler, doconnor, drosa, dsimansk, dymurray, eborisov, eglynn, fdeutsch, flucifre, gkamathe, gmeno, gparvin, groman, jbalunas, jburrell, jeder, jforrest, jjoyce, jkoehler, jmatthew, jprabhak, jpretori, jschluet, jwendell, kingland, kverlaen, lball, lhh, lphiri, lsvaty, manissin, matzew, mbenjamin, mburns, mgarciac, mhackett, mnovotny, ngough, njean, nobody, oramraz, owatkins, padillon, pahickey, pgrist, phoracek, pierdipi, rcernich, rguimara, rhaigner, rhel-process-autobot, rhos-maint, rhuss, rjohnson, sausingh, sdawley, smullick, sostapov, stirabos, suppawar, teagle, thason, twalsh, vereddy, veshanka, watson-tool-maintainers, whayutin, wtam |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | Flags: | phoracek:
needinfo?
(ahanwate) |
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | v0.31.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2331920, 2331921, 2331922, 2331928, 2331929, 2331930, 2331938, 2331917, 2331919, 2331923, 2331924, 2331925, 2331926, 2331927, 2331931, 2331932, 2331933, 2331934, 2331935, 2331936, 2331937, 2331939, 2331940, 2331941, 2331942, 2331943, 2331944, 2331945, 2331946, 2331947, 2331948, 2331949, 2331950, 2331951, 2331952, 2331953, 2331954, 2331955, 2331956, 2331957, 2331958, 2331959, 2331960, 2331961, 2331962, 2331963, 2331964, 2331965, 2331966, 2331967, 2331968, 2331969, 2331970, 2331971, 2331972, 2331973, 2331974, 2331975, 2331976, 2331977, 2331978, 2331979, 2331980, 2331981, 2331982, 2331983, 2331984, 2331985, 2331986, 2331987, 2331988, 2331989, 2331990, 2331991, 2332003, 2332004, 2332005, 2332006, 2332007, 2332008, 2332009, 2332010, 2332012, 2332013, 2350499 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2024-12-11 19:01:18 UTC
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:0385 https://access.redhat.com/errata/RHSA-2025:0385 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0386 https://access.redhat.com/errata/RHSA-2025:0386 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.4 for RHEL 8 Via RHSA-2025:0552 https://access.redhat.com/errata/RHSA-2025:0552 This issue has been addressed in the following products: multicluster-globalhub 1.2 for RHEL 9 Via RHSA-2025:0560 https://access.redhat.com/errata/RHSA-2025:0560 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 Via RHSA-2025:0576 https://access.redhat.com/errata/RHSA-2025:0576 This issue has been addressed in the following products: multicluster-globalhub 1.3 for RHEL 9 Via RHSA-2025:0577 https://access.redhat.com/errata/RHSA-2025:0577 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.5 for RHEL 9 multicluster engine for Kubernetes 2.5 for RHEL 8 Via RHSA-2025:0676 https://access.redhat.com/errata/RHSA-2025:0676 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 Via RHSA-2025:0679 https://access.redhat.com/errata/RHSA-2025:0679 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.7 for RHEL 9 multicluster engine for Kubernetes 2.7 for RHEL 8 Via RHSA-2025:0723 https://access.redhat.com/errata/RHSA-2025:0723 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:0653 https://access.redhat.com/errata/RHSA-2025:0653 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.6 for RHEL 9 multicluster engine for Kubernetes 2.6 for RHEL 8 Via RHSA-2025:0778 https://access.redhat.com/errata/RHSA-2025:0778 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 Via RHSA-2025:0785 https://access.redhat.com/errata/RHSA-2025:0785 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:0649 https://access.redhat.com/errata/RHSA-2025:0649 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:0645 https://access.redhat.com/errata/RHSA-2025:0645 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 Via RHSA-2025:0851 https://access.redhat.com/errata/RHSA-2025:0851 This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2025:0892 https://access.redhat.com/errata/RHSA-2025:0892 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:0839 https://access.redhat.com/errata/RHSA-2025:0839 This issue has been addressed in the following products: gatekeeper 3.17 for RHEL 9 Via RHSA-2025:1331 https://access.redhat.com/errata/RHSA-2025:1331 This issue has been addressed in the following products: gatekeeper 3.15 for RHEL 9 Via RHSA-2025:1332 https://access.redhat.com/errata/RHSA-2025:1332 This issue has been addressed in the following products: gatekeeper 3.14 for RHEL 9 Via RHSA-2025:1333 https://access.redhat.com/errata/RHSA-2025:1333 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.5 Via RHSA-2025:1334 https://access.redhat.com/errata/RHSA-2025:1334 This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.4 Via RHSA-2025:1468 https://access.redhat.com/errata/RHSA-2025:1468 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:1451 https://access.redhat.com/errata/RHSA-2025:1451 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2024:6121 https://access.redhat.com/errata/RHSA-2024:6121 This issue has been addressed in the following products: RHODF-4.17-RHEL-9 Via RHSA-2025:1824 https://access.redhat.com/errata/RHSA-2025:1824 This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:1829 https://access.redhat.com/errata/RHSA-2025:1829 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:1710 https://access.redhat.com/errata/RHSA-2025:1710 This issue has been addressed in the following products: RHODF-4.18-RHEL-9 Via RHSA-2025:2652 https://access.redhat.com/errata/RHSA-2025:2652 This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.14 Via RHSA-2025:3069 https://access.redhat.com/errata/RHSA-2025:3069 This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:3542 https://access.redhat.com/errata/RHSA-2025:3542 This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:3560 https://access.redhat.com/errata/RHSA-2025:3560 This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2025:8244 https://access.redhat.com/errata/RHSA-2025:8244 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2024:11037 https://access.redhat.com/errata/RHSA-2024:11037 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2024:11038 https://access.redhat.com/errata/RHSA-2024:11038 This issue has been addressed in the following products: OADP-1.4-RHEL-9 Via RHSA-2025:11396 https://access.redhat.com/errata/RHSA-2025:11396 |