VDB
RHSA-2025%3A0390
RHSA-2025%3A0390
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:38c172f30c0df809ae32802159f541425cd193e72be1f859890cdc186047ec12_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:38c172f30c0df809ae32802159f541425cd193e72be1f859890cdc186047ec12_arm64, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:68a2a90a6c4fda1c9fcae7d5b229b7c61bf400c9d440e11a8b7d8b08b886ee5c_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:68a2a90a6c4fda1c9fcae7d5b229b7c61bf400c9d440e11a8b7d8b08b886ee5c_arm64 |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:5bb0b143f10c31a2282fa89092791c340ddb0b69cd5f534867257693ba89a310_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:d7281f07f9ca7f59d694b6d1c6c5221db081001b3fde57bb11e23cf102fa59a6_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:482927e6074e3b9f8fdcbf177223939a136dfa635b94dd3cd7665e81b57fa7b0_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:482927e6074e3b9f8fdcbf177223939a136dfa635b94dd3cd7665e81b57fa7b0_arm64, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:0564b9ed6f54865bf9a515177a475a7690ed464f04b91806f30001dfe1bc8105_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:d0bf641dab7267af415a42d4e64b4d045771530a5b84056853c4fa0660eac99e_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:5bb0b143f10c31a2282fa89092791c340ddb0b69cd5f534867257693ba89a310_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:f0df0ad1ed07e33899fcda5b03599333fc5d545a22f7031b17e85e12dc983902_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:f0df0ad1ed07e33899fcda5b03599333fc5d545a22f7031b17e85e12dc983902_ppc64le |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:dfb6ee8b24108b93d3f074609d9795b7bd8b27429d9bfdc4652c1d1a9ef94448_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | * |
| Red Hat | registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:5c5e529da2197a702ae7ab6c344050492ac1df191cdee946657d966c432ca7ea_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/tempo-query-rhel8@sha256:5c5e529da2197a702ae7ab6c344050492ac1df191cdee946657d966c432ca7ea_amd64, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-rhel8-operator@sha256:d7281f07f9ca7f59d694b6d1c6c5221db081001b3fde57bb11e23cf102fa59a6_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-rhel8@sha256:9c553a6d61fb24e081f3b97793c12ee12f1a49d7b4d965b42948cf5281e70e6e_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/tempo-rhel8@sha256:9c553a6d61fb24e081f3b97793c12ee12f1a49d7b4d965b42948cf5281e70e6e_s390x |
| Red Hat | registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:40de7eafe0d7a2e9420e847489f1395e6b087b079075a492b86cf11dcca506d5_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:f0df0ad1ed07e33899fcda5b03599333fc5d545a22f7031b17e85e12dc983902_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:f0df0ad1ed07e33899fcda5b03599333fc5d545a22f7031b17e85e12dc983902_ppc64le |
| Red Hat | registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8@sha256:2a28795ce0bca193bcccf906e87410cf9ba46dd710c5513222117e2e7142068a_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | * |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:d0bf641dab7267af415a42d4e64b4d045771530a5b84056853c4fa0660eac99e_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/tempo-gateway-rhel8@sha256:d0bf641dab7267af415a42d4e64b4d045771530a5b84056853c4fa0660eac99e_ppc64le |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:68a2a90a6c4fda1c9fcae7d5b229b7c61bf400c9d440e11a8b7d8b08b886ee5c_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:68a2a90a6c4fda1c9fcae7d5b229b7c61bf400c9d440e11a8b7d8b08b886ee5c_arm64 |
| Red Hat | registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8@sha256:deb0c57d4d62e25e223487dc55c0743c96fc1e99a1115d9fc72499a2571317a3_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
…and 32 more
Timeline
- Jan 16, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:0390 advisory
- https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/distributed_tracing/distributed-tracing-platform-tempo advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0390.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory