VDB
RHSA-2025%3A0577
RHSA-2025%3A0577
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b2691b64e3f2a8e96709027ccadc580a38856d86f09dc1a9bad6cc756d5889bc_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b2691b64e3f2a8e96709027ccadc580a38856d86f09dc1a9bad6cc756d5889bc_ppc64le |
| Red Hat | multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:f908d7a3053aed87291b315cbf9a9c96dc905b0eca88e86d61024760760e094c_s390x as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:f908d7a3053aed87291b315cbf9a9c96dc905b0eca88e86d61024760760e094c_s390x |
| Red Hat | multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:9f590dd38a6efaebc80347c2c9f791dfe3d53c145084f167133d88fe1ad536d1_s390x as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:9f590dd38a6efaebc80347c2c9f791dfe3d53c145084f167133d88fe1ad536d1_s390x |
| Red Hat | multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:6c791d9455e45619be6c621e8da4c5f8ee9a79d091a6a85210ab354ee5145146_amd64 as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:6c791d9455e45619be6c621e8da4c5f8ee9a79d091a6a85210ab354ee5145146_amd64 |
| Red Hat | multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:ef551dc139eb1ee2eb8c89d91dafd1dacf665a86dfd9d93fc742ac3564460b33_arm64 as a component of multicluster-globalhub 1.3 for RHEL 9 | *, multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:ef551dc139eb1ee2eb8c89d91dafd1dacf665a86dfd9d93fc742ac3564460b33_arm64, * |
| Red Hat | multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:f908d7a3053aed87291b315cbf9a9c96dc905b0eca88e86d61024760760e094c_s390x as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:f908d7a3053aed87291b315cbf9a9c96dc905b0eca88e86d61024760760e094c_s390x, *, * |
| Red Hat | multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9@sha256:3fbe1053c181088b13507ea393321a7629274ba0988dcb557fccbf9108b982c0_amd64 as a component of multicluster-globalhub 1.3 for RHEL 9 | *, *, multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9@sha256:3fbe1053c181088b13507ea393321a7629274ba0988dcb557fccbf9108b982c0_amd64 |
| Red Hat | multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9@sha256:85d00d0f5abab2ffd7c4606405335b66f98e6c31247f2235c7aedc00a163e0a3_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9@sha256:85d00d0f5abab2ffd7c4606405335b66f98e6c31247f2235c7aedc00a163e0a3_ppc64le |
| Red Hat | multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:18f7ad1bc7a9058153600f13e73c60a3bc3c533e613c03bf95ee7bbeb1cc5bfb_amd64 as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:18f7ad1bc7a9058153600f13e73c60a3bc3c533e613c03bf95ee7bbeb1cc5bfb_amd64 |
| Red Hat | multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:81d683b1267eb710471d88a8f4d1d2639fc82387e163c720bc2477bd0d2072b8_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | *, *, multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:81d683b1267eb710471d88a8f4d1d2639fc82387e163c720bc2477bd0d2072b8_ppc64le |
| Red Hat | multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:c6e64d252f2e0383ce2aa28b3ca5542569a7778fb9ec683af5cdc65c9038b783_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | *, *, * |
| Red Hat | multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:97716544f06f5f273ebe9b798e9ea447d154f77715856554ad16cbe0b40cd18e_arm64 as a component of multicluster-globalhub 1.3 for RHEL 9 | * |
| Red Hat | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b2691b64e3f2a8e96709027ccadc580a38856d86f09dc1a9bad6cc756d5889bc_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | *, *, multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b2691b64e3f2a8e96709027ccadc580a38856d86f09dc1a9bad6cc756d5889bc_ppc64le |
| Red Hat | multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:61dce3a1ca2712f1c0cebd647f2f4e60ec66d64bda21de05dbb4f4f53e76d6f7_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | *, *, multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:61dce3a1ca2712f1c0cebd647f2f4e60ec66d64bda21de05dbb4f4f53e76d6f7_ppc64le |
| Red Hat | multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:915b21c4da77c85256cd3c85f743cbb898844164643cf306396510b5a56de507_ppc64le as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:915b21c4da77c85256cd3c85f743cbb898844164643cf306396510b5a56de507_ppc64le, *, * |
| Red Hat | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b6d552cbf8a4e75c05019b7d9d66e53007037fcb911b384720316228325c203e_amd64 as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b6d552cbf8a4e75c05019b7d9d66e53007037fcb911b384720316228325c203e_amd64 |
| Red Hat | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:ab94c51d19ffb5d0dc6628fef10425c93912ceef3e331d98141b3c8a73611984_s390x as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:ab94c51d19ffb5d0dc6628fef10425c93912ceef3e331d98141b3c8a73611984_s390x |
| Red Hat | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b6d552cbf8a4e75c05019b7d9d66e53007037fcb911b384720316228325c203e_amd64 as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:b6d552cbf8a4e75c05019b7d9d66e53007037fcb911b384720316228325c203e_amd64, *, * |
| Red Hat | multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:9cefca3314ca01a16aaafa13e273bfb2b4c52366a6b2459207cb92ce3c909be9_arm64 as a component of multicluster-globalhub 1.3 for RHEL 9 | *, *, multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:9cefca3314ca01a16aaafa13e273bfb2b4c52366a6b2459207cb92ce3c909be9_arm64 |
| Red Hat | multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9@sha256:3fbe1053c181088b13507ea393321a7629274ba0988dcb557fccbf9108b982c0_amd64 as a component of multicluster-globalhub 1.3 for RHEL 9 | multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9@sha256:3fbe1053c181088b13507ea393321a7629274ba0988dcb557fccbf9108b982c0_amd64 |
…and 38 more
Timeline
- Jan 22, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:0577 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://issues.redhat.com/browse/ACM-16468 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0577.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
…and 1 more