CVE-2020-9283

SOURCE - github

Summary

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

EPSS Score: 0.24388 (0.966)

Common Weakness Enumeration (CWE)

SOURCE - nist

Improper Verification of Cryptographic Signature

SOURCE - github

Improper Verification of Cryptographic Signature

SOURCE - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Improper Verification of Cryptographic Signature

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

SOURCE - redhat

Improper Handling of Length Parameter Inconsistency


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in