We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Advisory GHSA-67fw-w8f2-88wp references a vulnerability in the following Go modules:
Description: An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
ssh.InsecureIgnoreHostKey()
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING modules: - module: github.com/casdoor/casdoor non_go_versions: - introduced: TODO (earliest fixed "", vuln range ">= 1.541.0, <= 1.636.0") vulnerable_at: 1.659.0 summary: casdoor's use of`ssh.InsecureIgnoreHostKey()` disables host key verification in github.com/casdoor/casdoor cves: - CVE-2024-41264 ghsas: - GHSA-67fw-w8f2-88wp references: - advisory: https://github.com/advisories/GHSA-67fw-w8f2-88wp - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-41264 - web: https://gist.github.com/nyxfqq/33ceaccbc9b05d439a944c2b55fa1c0f - web: https://github.com/casdoor/casdoor/blob/v1.636.0/object/viaSSHDialer.go source: id: GHSA-67fw-w8f2-88wp created: 2024-08-02T14:02:56.414611863Z review_status: UNREVIEWED
The text was updated successfully, but these errors were encountered:
Change https://go.dev/cl/603235 mentions this issue: data/reports: add 29 unreviewed reports
data/reports: add 29 unreviewed reports
Sorry, something went wrong.
7162f20
No branches or pull requests
Advisory GHSA-67fw-w8f2-88wp references a vulnerability in the following Go modules:
Description:
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the
ssh.InsecureIgnoreHostKey()
method.References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: