VDB
RHSA-2025%3A0522
RHSA-2025%3A0522
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhosdt/jaeger-ingester-rhel8@sha256:b859148721ef0e1858586cc34ed89d005c64167e340de3a7702090c89d9d1209_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, registry.redhat.io/rhosdt/jaeger-ingester-rhel8@sha256:b859148721ef0e1858586cc34ed89d005c64167e340de3a7702090c89d9d1209_s390x |
| Red Hat | registry.redhat.io/rhosdt/jaeger-query-rhel8@sha256:1f13668479ff701caaf6bc9d3ff27234ceecf6f10eed81dc5ece1b380b4e15f3_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, registry.redhat.io/rhosdt/jaeger-query-rhel8@sha256:1f13668479ff701caaf6bc9d3ff27234ceecf6f10eed81dc5ece1b380b4e15f3_amd64 |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8@sha256:56e4c319d7c125148913e556564adc4a463cc6ec9763f8acc3c25dd2030b174a_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8@sha256:56e4c319d7c125148913e556564adc4a463cc6ec9763f8acc3c25dd2030b174a_amd64 |
| Red Hat | registry.redhat.io/rhosdt/jaeger-rhel8-operator@sha256:3087b2c66b04b6877bbd7c104c70cea5f7c692b6137c96751ccbff726886676f_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8@sha256:cb0c08a16a23196aaee5a3465b96eb9ea20a6867bd2fff35368563c2184dc762_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8@sha256:cb0c08a16a23196aaee5a3465b96eb9ea20a6867bd2fff35368563c2184dc762_amd64 |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8@sha256:e4c891e4398e4b555d66a1c8fa5e38ce75b3105eda3e86b6cfac5807fb30714c_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8@sha256:e4c891e4398e4b555d66a1c8fa5e38ce75b3105eda3e86b6cfac5807fb30714c_arm64 |
| Red Hat | registry.redhat.io/rhosdt/jaeger-ingester-rhel8@sha256:b859148721ef0e1858586cc34ed89d005c64167e340de3a7702090c89d9d1209_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-ingester-rhel8@sha256:b859148721ef0e1858586cc34ed89d005c64167e340de3a7702090c89d9d1209_s390x |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8@sha256:a63888f881b136cfaf7a4ee8f3498dd508a117363035385bebe361463bd1425c_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8@sha256:a63888f881b136cfaf7a4ee8f3498dd508a117363035385bebe361463bd1425c_s390x, *, * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-rhel8-operator@sha256:b48ab8e510e1f9a632a6fbf08cbebeb30597f29a199473022f3b4550684587a4_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-rhel8-operator@sha256:b48ab8e510e1f9a632a6fbf08cbebeb30597f29a199473022f3b4550684587a4_s390x |
| Red Hat | registry.redhat.io/rhosdt/jaeger-collector-rhel8@sha256:5ed2e26a0997a3c9707851370dd701f1b921683c250f22dd8fbf42fa2ba504df_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-collector-rhel8@sha256:5ed2e26a0997a3c9707851370dd701f1b921683c250f22dd8fbf42fa2ba504df_s390x |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8@sha256:f9cec96a7c2d3f78d39b801d4fc1849e9b81cd0b07d8646ec26d75e8dd60a0ad_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8@sha256:1f153c0a469504735e08a6ca0b4f2c40abd2544ddcaf8d319ebc184ca90fbb5e_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8@sha256:1f153c0a469504735e08a6ca0b4f2c40abd2544ddcaf8d319ebc184ca90fbb5e_ppc64le |
| Red Hat | registry.redhat.io/rhosdt/jaeger-collector-rhel8@sha256:a8baa99bcc8a138eac44c74dd93dc67399d39124266f193fb4bb6152b2168909_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-collector-rhel8@sha256:a8baa99bcc8a138eac44c74dd93dc67399d39124266f193fb4bb6152b2168909_ppc64le, *, * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8@sha256:a63888f881b136cfaf7a4ee8f3498dd508a117363035385bebe361463bd1425c_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8@sha256:a63888f881b136cfaf7a4ee8f3498dd508a117363035385bebe361463bd1425c_s390x |
| Red Hat | registry.redhat.io/rhosdt/jaeger-collector-rhel8@sha256:5ed2e26a0997a3c9707851370dd701f1b921683c250f22dd8fbf42fa2ba504df_s390x as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, registry.redhat.io/rhosdt/jaeger-collector-rhel8@sha256:5ed2e26a0997a3c9707851370dd701f1b921683c250f22dd8fbf42fa2ba504df_s390x |
| Red Hat | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8@sha256:3e3d042ca0846b586fd71f1ebb031cca079b2fa7a30dbf71f809b6bcb910244b_ppc64le as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8@sha256:3e3d042ca0846b586fd71f1ebb031cca079b2fa7a30dbf71f809b6bcb910244b_ppc64le |
| Red Hat | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8@sha256:ddddee551b77222714cd9a9e47752e171cc900623bd77800269dead71452fe72_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8@sha256:ddddee551b77222714cd9a9e47752e171cc900623bd77800269dead71452fe72_arm64, *, * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-agent-rhel8@sha256:36911a85237e694a9d25b1d552099ac7b8857885df699321b342e896d6cda2a2_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, registry.redhat.io/rhosdt/jaeger-agent-rhel8@sha256:36911a85237e694a9d25b1d552099ac7b8857885df699321b342e896d6cda2a2_arm64, * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8@sha256:7619729065c5e34d88cfdaab6ed2fded897921e463d767b5d15b6d182e9e05a7_arm64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
| Red Hat | registry.redhat.io/rhosdt/jaeger-rhel8-operator@sha256:7401dc7124e10ef4d9c8dc195c975543551c55b211e253a1ff19ae6586b43032_amd64 as a component of Red Hat OpenShift distributed tracing 3.4 | *, *, * |
…and 47 more
Timeline
- Jan 21, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:0522 advisory
- https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/distributed_tracing/distributed-tracing-platform-jaeger advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0522.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory