VDB
RHSA-2025%3A1333
RHSA-2025%3A1333
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:4a839671cab110692b666eb52220c60e2372e65fa0ebccb59638469e3c4759b2_arm64 as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9-operator@sha256:4a839671cab110692b666eb52220c60e2372e65fa0ebccb59638469e3c4759b2_arm64 |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:4a839671cab110692b666eb52220c60e2372e65fa0ebccb59638469e3c4759b2_arm64 as a component of gatekeeper 3.14 for RHEL 9 | *, *, * |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:d04a5d2ee3b584a2d5a6c00c526466fe83c6f1ffa59cfea9f808fcb6b6389ea4_s390x as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9-operator@sha256:d04a5d2ee3b584a2d5a6c00c526466fe83c6f1ffa59cfea9f808fcb6b6389ea4_s390x |
| golang | ||
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:eb043a5480b483f90e656a4cd4189b6672c6856072deaaad7f082bba9818886d_s390x as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9@sha256:eb043a5480b483f90e656a4cd4189b6672c6856072deaaad7f082bba9818886d_s390x |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:242dc311770f135c2e8e90213d2df37be4efbe9d933a6002d14bf8e0189c2240_ppc64le as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9-operator@sha256:242dc311770f135c2e8e90213d2df37be4efbe9d933a6002d14bf8e0189c2240_ppc64le |
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:eb043a5480b483f90e656a4cd4189b6672c6856072deaaad7f082bba9818886d_s390x as a component of gatekeeper 3.14 for RHEL 9 | *, gatekeeper/gatekeeper-rhel9@sha256:eb043a5480b483f90e656a4cd4189b6672c6856072deaaad7f082bba9818886d_s390x, * |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:5a598b8847f91274791e75c8338c177774fb1557d5ca600e90da5a59a4afb82a_amd64 as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9-operator@sha256:5a598b8847f91274791e75c8338c177774fb1557d5ca600e90da5a59a4afb82a_amd64 |
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:2a5ea0af3692ba39a4dfef001596015690079068bc3f6ccbf02bfbcffac240ab_amd64 as a component of gatekeeper 3.14 for RHEL 9 | *, *, * |
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:2a5ea0af3692ba39a4dfef001596015690079068bc3f6ccbf02bfbcffac240ab_amd64 as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9@sha256:2a5ea0af3692ba39a4dfef001596015690079068bc3f6ccbf02bfbcffac240ab_amd64 |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:5a598b8847f91274791e75c8338c177774fb1557d5ca600e90da5a59a4afb82a_amd64 as a component of gatekeeper 3.14 for RHEL 9 | *, *, * |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:242dc311770f135c2e8e90213d2df37be4efbe9d933a6002d14bf8e0189c2240_ppc64le as a component of gatekeeper 3.14 for RHEL 9 | *, gatekeeper/gatekeeper-rhel9-operator@sha256:242dc311770f135c2e8e90213d2df37be4efbe9d933a6002d14bf8e0189c2240_ppc64le, * |
| Red Hat | gatekeeper/gatekeeper-operator-bundle@sha256:e2a1515489022d6ae4a310f8a9c6432084ec6f0ca83e02401cbba17d99c5ec3c_amd64 as a component of gatekeeper 3.14 for RHEL 9 | * |
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:0750fea44fdbb31437d102b7f0e3878fc5bbc79284c1ffb8fbafb7586f7b2b4d_ppc64le as a component of gatekeeper 3.14 for RHEL 9 | *, *, * |
| golang | x/crypto/ssh | |
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:0750fea44fdbb31437d102b7f0e3878fc5bbc79284c1ffb8fbafb7586f7b2b4d_ppc64le as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9@sha256:0750fea44fdbb31437d102b7f0e3878fc5bbc79284c1ffb8fbafb7586f7b2b4d_ppc64le |
| Red Hat | gatekeeper/gatekeeper-operator-bundle@sha256:e2a1515489022d6ae4a310f8a9c6432084ec6f0ca83e02401cbba17d99c5ec3c_amd64 as a component of gatekeeper 3.14 for RHEL 9 | *, *, * |
| Red Hat | gatekeeper/gatekeeper-rhel9-operator@sha256:d04a5d2ee3b584a2d5a6c00c526466fe83c6f1ffa59cfea9f808fcb6b6389ea4_s390x as a component of gatekeeper 3.14 for RHEL 9 | *, *, gatekeeper/gatekeeper-rhel9-operator@sha256:d04a5d2ee3b584a2d5a6c00c526466fe83c6f1ffa59cfea9f808fcb6b6389ea4_s390x |
| Red Hat | gatekeeper/gatekeeper-rhel9@sha256:2e14b2661e4bc2d592862c2cc62993ad25c016166157d0566d798830b9da17c5_arm64 as a component of gatekeeper 3.14 for RHEL 9 | gatekeeper/gatekeeper-rhel9@sha256:2e14b2661e4bc2d592862c2cc62993ad25c016166157d0566d798830b9da17c5_arm64 |
…and 1 more
Timeline
- Feb 12, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:1333 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.14.0 advisory
- https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.14.1 advisory
- https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.14.2 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://issues.redhat.com/browse/HYPBLD-547 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1333.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
…and 4 more