VDB
RHSA-2025%3A1841
RHSA-2025%3A1841
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:0fdd5e119325e8c30f5ef0da9b0a78469143a3d222e8b92d0d972acbed8db99c_amd64 as a component of Red Hat Trusted Artifact Signer 1.1 | *, registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:0fdd5e119325e8c30f5ef0da9b0a78469143a3d222e8b92d0d972acbed8db99c_amd64, * |
| Red Hat | Red Hat Trusted Artifact Signer | |
| Red Hat | registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:0fdd5e119325e8c30f5ef0da9b0a78469143a3d222e8b92d0d972acbed8db99c_amd64 as a component of Red Hat Trusted Artifact Signer 1.1 | registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:0fdd5e119325e8c30f5ef0da9b0a78469143a3d222e8b92d0d972acbed8db99c_amd64 |
| Red Hat | registry.redhat.io/rhtas/timestamp-authority-rhel9@sha256:0fdd5e119325e8c30f5ef0da9b0a78469143a3d222e8b92d0d972acbed8db99c_amd64 as a component of Red Hat Trusted Artifact Signer 1.1 |
Timeline
- Feb 25, 2025 CVE Published
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- Jul 5, 2026 Distribution Patch
- Jul 5, 2026 Security Advisory
- Jul 5, 2026 Security Advisory
- Jul 13, 2026 CVE Updated
References
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://access.redhat.com/errata/RHSA-2025:1841 advisory
- https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.1 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://go.dev/cl/637536 advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
- https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.1/html-single/release_notes/index advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1841.json advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
…and 2 more