CVE-2024-45337: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

0.0 CVSS

Description

Applications and libraries which misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass.

Classification

CVE ID: CVE-2024-45337

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: golang.org/x/crypto

Product: golang.org/x/crypto/ssh

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.85% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://go.dev/issue/70779
https://go.dev/cl/635315
https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ
https://pkg.go.dev/vuln/GO-2024-3321

Timeline