An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
References:GSA_kwCzR0hTQS04d3h4LTM1cWMtdnA2cs4AA9f9
Missing key verification in gost
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
go:github.com/ginuerzh/gost | <= 2.11.5 | No known fixed version | |
Affected Version RangesAll affected versions2.6.1 |