VDB
RHSA-2025%3A15680
RHSA-2025%3A15680
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator@sha256:857571fac1057b318fbf7c1ffcfc54f34f8df96c7d5645f70c57722f309d75ad_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator@sha256:857571fac1057b318fbf7c1ffcfc54f34f8df96c7d5645f70c57722f309d75ad_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-config-api-rhel9@sha256:31ea2cbdbe431a14c6304cee710bb9d1c3c0eabb69635d38952ac367219c7d8d_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-cluster-config-api-rhel9@sha256:31ea2cbdbe431a14c6304cee710bb9d1c3c0eabb69635d38952ac367219c7d8d_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-powervs-machine-controllers-rhel9@sha256:1cc5c6b46db2a8c8ce9d955f945141b1ed39b371d46e747fff5ef9112f0f907a_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | registry.redhat.io/openshift4/ose-installer-altinfra-rhel9@sha256:d33e7ed943a46ce235ae55b8fafd9364775bf35e42faa59c7c10e0cb3d94582a_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-installer-altinfra-rhel9@sha256:d33e7ed943a46ce235ae55b8fafd9364775bf35e42faa59c7c10e0cb3d94582a_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-cluster-api-controllers-rhel9@sha256:4cdf2f41f7d507ab3811d890f9407f4dca492ac923b456634226d8f3bc2375a7_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | registry.redhat.io/openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:b1ac957a8c12628c42852b69e562ec9d89b0ce5c6d15d6ad58f27ee6acb66d49_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:b1ac957a8c12628c42852b69e562ec9d89b0ce5c6d15d6ad58f27ee6acb66d49_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-docker-builder-rhel9@sha256:33004ed62cd9d071599867929b8988e5b407bc321b7e9f29a1f46e684404ea2f_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-docker-builder-rhel9@sha256:33004ed62cd9d071599867929b8988e5b407bc321b7e9f29a1f46e684404ea2f_amd64 |
| Red Hat | registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:0786dd4725983759b9d529df3973e98e831d56ee568cd3472cd2f37d894617e4_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-policy-controller-rhel9@sha256:b866e2b90b49ad794143637055a677992663d88a528e59bc0d3fd78913408b5d_s390x as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-cluster-policy-controller-rhel9@sha256:b866e2b90b49ad794143637055a677992663d88a528e59bc0d3fd78913408b5d_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator@sha256:810ed0e13643e69d0eb897211ee91c9c2fed52ff3d37c68fff0878a05dc94f2d_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator@sha256:810ed0e13643e69d0eb897211ee91c9c2fed52ff3d37c68fff0878a05dc94f2d_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-tools-rhel9@sha256:705e61ea9593f81e305d1c5126d46b412ecb7c3a2327c2e6a161135273793f99_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-tools-rhel9@sha256:705e61ea9593f81e305d1c5126d46b412ecb7c3a2327c2e6a161135273793f99_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:e1249bf0f3cb7e17f519c66db0e3c655d7cbbdbe2136d9c5444294d28a43bef9_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:e1249bf0f3cb7e17f519c66db0e3c655d7cbbdbe2136d9c5444294d28a43bef9_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-openstack-cinder-csi-driver-rhel9-operator@sha256:450b4dd93022327e1fc6a8eaf2fb768f55e04781b6764fde601d653223e19b1f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-openstack-cinder-csi-driver-rhel9-operator@sha256:450b4dd93022327e1fc6a8eaf2fb768f55e04781b6764fde601d653223e19b1f_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:da9f4301b1d4468e2ff2258e0c077cbfdbfb8413836b079b33af88887852fec1_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:da9f4301b1d4468e2ff2258e0c077cbfdbfb8413836b079b33af88887852fec1_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-livenessprobe-rhel9@sha256:7b1c93b4713d1d4de7cb57728ee29da09657e8561eee127d04609127e744c61e_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-csi-livenessprobe-rhel9@sha256:7b1c93b4713d1d4de7cb57728ee29da09657e8561eee127d04609127e744c61e_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-prometheus-rhel9-operator@sha256:79a360820f48119eb258fbc5cedff868dcf8b324edfd124a7985d8ce980fae8d_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-prometheus-rhel9-operator@sha256:79a360820f48119eb258fbc5cedff868dcf8b324edfd124a7985d8ce980fae8d_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-webhook-rhel9@sha256:e17353bd25c3f15381c81a220c2780c772e461485c3cc58f5bd2d8ded2487b9e_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-webhook-rhel9@sha256:e17353bd25c3f15381c81a220c2780c772e461485c3cc58f5bd2d8ded2487b9e_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-multus-cni-rhel9@sha256:dea0f4137664ce1d779c76b3ebbc1f32e313b1035b6b37a91f2cda1e0a66baad_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-multus-cni-rhel9@sha256:dea0f4137664ce1d779c76b3ebbc1f32e313b1035b6b37a91f2cda1e0a66baad_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-snapshot-controller-rhel9@sha256:146f743ac6967553af0446a6e2171e323eb8932ce077cfdad53b15334b1098e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-csi-snapshot-controller-rhel9@sha256:146f743ac6967553af0446a6e2171e323eb8932ce077cfdad53b15334b1098e1_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-csi-snapshot-validation-webhook-rhel9@sha256:76fe8af4570de03dd132a76d77a01a848afc8929551920f1747340916d1d7cc4_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-csi-snapshot-validation-webhook-rhel9@sha256:76fe8af4570de03dd132a76d77a01a848afc8929551920f1747340916d1d7cc4_arm64 |
…and 1292 more
Timeline
- Sep 17, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:15680 advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_15680.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory