CVE Vulnerabilities

CVE-2020-9283

Improper Verification of Cryptographic Signature

Published: Feb 20, 2020 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Package_ssh Golang 0.0.0-20200220183623-bac4c82f6975 (including) 0.0.0-20200220183623-bac4c82f6975 (including)
3scale API Management 2.10 on RHEL 7 RedHat 3scale-amp2/3scale-rhel7-operator:1.13.0-17 *
3scale API Management 2.10 on RHEL 7 RedHat 3scale-amp2/3scale-rhel7-operator-metadata:2.10.0-38 *
3scale API Management 2.10 on RHEL 7 RedHat 3scale-amp2/apicast-rhel7-operator:1.13.0-4 *
3scale API Management 2.10 on RHEL 7 RedHat 3scale-amp2/apicast-rhel7-operator-metadata:2.10.0-9 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-agent-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-all-in-one-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-collector-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-es-index-cleaner-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-es-rollover-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-ingester-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-query-rhel7:1.17.6-1 *
Jaeger-1.17 RedHat distributed-tracing/jaeger-rhel7-operator:1.17.6-1 *
OpenShift Service Mesh 1.0 RedHat openshift-service-mesh/3scale-istio-adapter-rhel8:1.0.0-8 *
Openshift Service Mesh 1.1 RedHat kiali-0:v1.12.10.redhat2-1.el7 *
OpenShift Service Mesh 1.1 RedHat ior-0:1.1.6-1.el8 *
OpenShift Service Mesh 1.1 RedHat servicemesh-0:1.1.6-1.el8 *
OpenShift Service Mesh 1.1 RedHat servicemesh-cni-0:1.1.6-1.el8 *
OpenShift Service Mesh 1.1 RedHat servicemesh-grafana-0:6.4.3-13.el8 *
OpenShift Service Mesh 1.1 RedHat servicemesh-operator-0:1.1.6-2.el8 *
OpenShift Service Mesh 1.1 RedHat servicemesh-prometheus-0:2.14.0-14.el8 *
Red Hat OpenShift Container Platform 4 RedHat atomic-openshift-cluster-autoscaler-container *
Red Hat OpenShift Container Platform 4 RedHat baremetal-machine-controller-container *
Red Hat OpenShift Container Platform 4 RedHat cluster-monitoring-operator-container *
Red Hat OpenShift Container Platform 4 RedHat cluster-network-operator-container *
Red Hat OpenShift Container Platform 4 RedHat cluster-node-tuning-operator-container *
Red Hat OpenShift Container Platform 4 RedHat cluster-version-operator-container *
Red Hat OpenShift Container Platform 4 RedHat configmap-reload-container *
Red Hat OpenShift Container Platform 4 RedHat coredns-container *
Red Hat OpenShift Container Platform 4 RedHat golang-github-openshift-oauth-proxy-container *
Red Hat OpenShift Container Platform 4 RedHat golang-github-prometheus-alertmanager-container *
Red Hat OpenShift Container Platform 4 RedHat golang-github-prometheus-node_exporter-container *
Red Hat OpenShift Container Platform 4 RedHat golang-github-prometheus-prometheus-container *
Red Hat OpenShift Container Platform 4 RedHat grafana-container *
Red Hat OpenShift Container Platform 4 RedHat ironic-container *
Red Hat OpenShift Container Platform 4 RedHat ironic-hardware-inventory-recorder-image-container *
Red Hat OpenShift Container Platform 4 RedHat ironic-inspector-container *
Red Hat OpenShift Container Platform 4 RedHat ironic-ipa-downloader-container *
Red Hat OpenShift Container Platform 4 RedHat ironic-rhcos-downloader-container *
Red Hat OpenShift Container Platform 4 RedHat ironic-static-ip-manager-container *
Red Hat OpenShift Container Platform 4 RedHat jenkins-agent-maven-35-rhel7-container *
Red Hat OpenShift Container Platform 4 RedHat kube-proxy-container *
Red Hat OpenShift Container Platform 4 RedHat kube-rbac-proxy-container *
Red Hat OpenShift Container Platform 4 RedHat kube-state-metrics-container *
Red Hat OpenShift Container Platform 4 RedHat kuryr-cni-container *
Red Hat OpenShift Container Platform 4 RedHat kuryr-controller-container *
Red Hat OpenShift Container Platform 4 RedHat local-storage-static-provisioner-container *
Red Hat OpenShift Container Platform 4 RedHat marketplace-operator-container *
Red Hat OpenShift Container Platform 4 RedHat multus-cni-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-builder-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-cli-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-console-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-console-operator-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-deployer-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-haproxy-router-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-hyperkube-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-keepalived-ipfailover-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-pod-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-registry-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-enterprise-tests-container *
Red Hat OpenShift Container Platform 4 RedHat openshift-jenkins-2-container *
Red Hat OpenShift Container Platform 4 RedHat operator-lifecycle-manager-container *
Red Hat OpenShift Container Platform 4 RedHat operator-registry-container *
Red Hat OpenShift Container Platform 4 RedHat ose-aws-machine-controllers-container *
Red Hat OpenShift Container Platform 4 RedHat ose-azure-machine-controllers-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cli-artifacts-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cloud-credential-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-authentication-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-autoscaler-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-bootstrap-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-config-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-dns-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-image-registry-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-ingress-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-kube-apiserver-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-kube-controller-manager-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-kube-scheduler-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-machine-approver-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-openshift-apiserver-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-openshift-controller-manager-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-samples-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-storage-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-cluster-update-keys-container *
Red Hat OpenShift Container Platform 4 RedHat ose-etcd-container *
Red Hat OpenShift Container Platform 4 RedHat ose-installer-artifacts-container *
Red Hat OpenShift Container Platform 4 RedHat ose-installer-container *
Red Hat OpenShift Container Platform 4 RedHat ose-libvirt-machine-controllers-container *
Red Hat OpenShift Container Platform 4 RedHat ose-machine-api-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-machine-config-operator-container *
Red Hat OpenShift Container Platform 4 RedHat ose-multus-admission-controller-container *
Red Hat OpenShift Container Platform 4 RedHat ose-must-gather-container *
Red Hat OpenShift Container Platform 4 RedHat ose-openshift-apiserver-container *
Red Hat OpenShift Container Platform 4 RedHat ose-openshift-controller-manager-container *
Red Hat OpenShift Container Platform 4 RedHat ose-openstack-machine-controllers-container *
Red Hat OpenShift Container Platform 4 RedHat ose-ovn-kubernetes-container *
Red Hat OpenShift Container Platform 4 RedHat ose-prometheus-adapter-container *
Red Hat OpenShift Container Platform 4 RedHat ose-service-ca-operator-container *
Red Hat OpenShift Container Platform 4 RedHat prometheus-config-reloader-container *
Red Hat OpenShift Container Platform 4 RedHat prometheus-operator-container *
Red Hat OpenShift Container Platform 4 RedHat prom-label-proxy-container *
Red Hat OpenShift Container Platform 4 RedHat telemeter-container *
Red Hat OpenShift Container Platform 4.3 RedHat openshift-clients-0:4.3.31-202007250052.p0.git.3329.59998b9.el7 *
Red Hat OpenShift Container Platform 4.3 RedHat openshift4/ose-azure-machine-controllers:v4.3.31-202007272153.p0 *
Red Hat OpenShift Container Platform 4.3 RedHat openshift4/ose-sriov-dp-admission-controller:v4.3.37-202009151447.p0 *
Red Hat OpenShift Container Platform 4.4 RedHat openshift4/ose-baremetal-rhel7-operator:v4.4.0-202006290400.p0 *
Red Hat OpenShift Container Platform 4.4 RedHat openshift4/ose-azure-machine-controllers:v4.4.0-202006290400.p0 *
Red Hat OpenShift Container Platform 4.4 RedHat openshift4/ose-descheduler:v4.4.0-202006290400.p0 *
Red Hat OpenShift Container Platform 4.4 RedHat openshift4/ose-cloud-credential-operator:v4.4.0-202007060343.p0 *
Red Hat OpenShift Container Platform 4.4 RedHat openshift4/ose-cluster-machine-approver:v4.4.0-202007171809.p0 *
Red Hat OpenShift Container Platform 4.5 RedHat openshift4/ose-cluster-logging-operator:v4.5.0-202007012112.p0 *
Red Hat OpenShift Container Platform 4.5 RedHat openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el8 *
Red Hat OpenShift Container Platform 4.5 RedHat openshift4/ose-cluster-kube-descheduler-operator:v4.5.0-202007131801.p0 *
Red Hat OpenShift Container Platform 4.5 RedHat openshift4/ose-descheduler:v4.5.0-202007101023.p0 *
Red Hat OpenShift Container Platform 4.6 RedHat openshift4/ose-elasticsearch-operator:v4.6.0-202010200139.p0 *
Red Hat OpenShift Virtualization 2 RedHat kubevirt-cpu-model-nfd-plugin-container *
Red Hat OpenShift Virtualization 2 RedHat kubevirt-cpu-node-labeller-container *
Red Hat OpenShift Virtualization 2 RedHat kubevirt-kvm-info-nfd-plugin-container *
Red Hat OpenShift Virtualization 2 RedHat vm-import-controller-container *
Golang-go.crypto Ubuntu bionic *
Golang-go.crypto Ubuntu eoan *
Golang-go.crypto Ubuntu esm-apps/bionic *
Golang-go.crypto Ubuntu esm-infra/xenial *
Golang-go.crypto Ubuntu xenial *
Mongo-tools Ubuntu bionic *
Mongo-tools Ubuntu eoan *
Mongo-tools Ubuntu trusty *
Snapd Ubuntu trusty *

References