CVE-2024-39223
published 2024-07-03CVE-2024-39223: An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.70%
48.8th percentile
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | ginuerzh_gost | 0 – 2.11.5 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Missing key verification in gost in github.com/ginuerzh/gost
osv·2024-10-28
CVE-2024-39223 Missing key verification in gost in github.com/ginuerzh/gost
Missing key verification in gost in github.com/ginuerzh/gost
Missing key verification in gost in github.com/ginuerzh/gost
OSV
CVE-2024-39223: An authentication bypass in the SSH service of gost v2
osv·2024-07-03·CVSS 9.8
CVE-2024-39223 [CRITICAL] CVE-2024-39223: An authentication bypass in the SSH service of gost v2
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
OSV
Missing key verification in gost
osv·2024-07-03
CVE-2024-39223 [CRITICAL] Missing key verification in gost
Missing key verification in gost
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
GHSA
Missing key verification in gost
ghsa·2024-07-03
CVE-2024-39223 [CRITICAL] CWE-289 Missing key verification in gost
Missing key verification in gost
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.github.com/nyxfqq/a7242170b1118e78436a62dee4e09e8ahttps://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229https://github.com/ginuerzh/gost/issues/1034https://gist.github.com/nyxfqq/a7242170b1118e78436a62dee4e09e8ahttps://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229https://github.com/ginuerzh/gost/issues/1034
2024-07-03
Published