CVE Vulnerabilities

CVE-2020-9283

Improper Verification of Cryptographic Signature

Published: Feb 20, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
Package_sshGolang0.0.0-20200220183623-bac4c82f6975 (including)0.0.0-20200220183623-bac4c82f6975 (including)
3scale API Management 2.10 on RHEL 7RedHat3scale-amp2/3scale-rhel7-operator:1.13.0-17*
3scale API Management 2.10 on RHEL 7RedHat3scale-amp2/3scale-rhel7-operator-metadata:2.10.0-38*
3scale API Management 2.10 on RHEL 7RedHat3scale-amp2/apicast-rhel7-operator:1.13.0-4*
3scale API Management 2.10 on RHEL 7RedHat3scale-amp2/apicast-rhel7-operator-metadata:2.10.0-9*
Jaeger-1.17RedHatdistributed-tracing/jaeger-agent-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-all-in-one-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-collector-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-es-index-cleaner-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-es-rollover-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-ingester-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-query-rhel7:1.17.6-1*
Jaeger-1.17RedHatdistributed-tracing/jaeger-rhel7-operator:1.17.6-1*
OpenShift Service Mesh 1.0RedHatopenshift-service-mesh/3scale-istio-adapter-rhel8:1.0.0-8*
Openshift Service Mesh 1.1RedHatkiali-0:v1.12.10.redhat2-1.el7*
OpenShift Service Mesh 1.1RedHatior-0:1.1.6-1.el8*
OpenShift Service Mesh 1.1RedHatservicemesh-0:1.1.6-1.el8*
OpenShift Service Mesh 1.1RedHatservicemesh-cni-0:1.1.6-1.el8*
OpenShift Service Mesh 1.1RedHatservicemesh-grafana-0:6.4.3-13.el8*
OpenShift Service Mesh 1.1RedHatservicemesh-operator-0:1.1.6-2.el8*
OpenShift Service Mesh 1.1RedHatservicemesh-prometheus-0:2.14.0-14.el8*
Red Hat OpenShift Container Platform 4.3RedHatopenshift-clients-0:4.3.31-202007250052.p0.git.3329.59998b9.el8*
Red Hat OpenShift Container Platform 4.3RedHatopenshift4/ose-azure-machine-controllers:v4.3.31-202007272153.p0*
Red Hat OpenShift Container Platform 4.3RedHatopenshift4/ose-sriov-dp-admission-controller:v4.3.37-202009151447.p0*
Red Hat OpenShift Container Platform 4.4RedHatopenshift4/ose-baremetal-rhel7-operator:v4.4.0-202006290400.p0*
Red Hat OpenShift Container Platform 4.4RedHatopenshift4/ose-azure-machine-controllers:v4.4.0-202006290400.p0*
Red Hat OpenShift Container Platform 4.4RedHatopenshift4/ose-descheduler:v4.4.0-202006290400.p0*
Red Hat OpenShift Container Platform 4.4RedHatopenshift4/ose-cloud-credential-operator:v4.4.0-202007060343.p0*
Red Hat OpenShift Container Platform 4.4RedHatopenshift4/ose-cluster-machine-approver:v4.4.0-202007171809.p0*
Red Hat OpenShift Container Platform 4.5RedHatopenshift4/ose-cluster-logging-operator:v4.5.0-202007012112.p0*
Red Hat OpenShift Container Platform 4.5RedHatopenshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el7*
Red Hat OpenShift Container Platform 4.5RedHatopenshift4/ose-cluster-kube-descheduler-operator:v4.5.0-202007131801.p0*
Red Hat OpenShift Container Platform 4.5RedHatopenshift4/ose-descheduler:v4.5.0-202007101023.p0*
Red Hat OpenShift Container Platform 4.6RedHatopenshift4/ose-elasticsearch-operator:v4.6.0-202010200139.p0*
Golang-go.cryptoUbuntubionic*
Golang-go.cryptoUbuntueoan*
Golang-go.cryptoUbuntuesm-apps/bionic*
Golang-go.cryptoUbuntuesm-infra/xenial*
Golang-go.cryptoUbuntuxenial*
Mongo-toolsUbuntubionic*
Mongo-toolsUbuntueoan*
Mongo-toolsUbuntufocal*
Mongo-toolsUbuntutrusty*
SnapdUbuntutrusty*

References