Github.Com Ginuerzh Gost vulnerabilities
2 known vulnerabilities affecting github.com/ginuerzh_gost.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-39223P3CRITICAL≥ 0, ≤ 2.11.52024-07-03
CVE-2024-39223 [CRITICAL] CWE-289 Missing key verification in gost
Missing key verification in gost
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
ghsaosv
CVE-2023-32691P4MEDIUM≥ 0, ≤ 2.11.52023-05-22
CVE-2023-32691 [MEDIUM] CWE-203 ginuerzh/gost vulnerable to Timing Attack
ginuerzh/gost vulnerable to Timing Attack
[Timing attacks](https://en.wikipedia.org/wiki/Timing_attack) occur when an attacker can guess a secret by observing a difference in processing time for valid and invalid inputs. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparision function.
More information on this attack type can be found in [this blog post](https://ve
ghsaosv