CVE-2024-39223 Information
Jul 04, 2024
cve
Description
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
Reference
https://github.com/ginuerzh/gost/issues/1034 https://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229 https://gist.github.com/nyxfqq/a7242170b1118e78436a62dee4e09e8a
Share on: