The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a no-touch-required extension in Permissions.Extensions from PublicKeyCallback.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Crypto | Golang | * | 0.52.0 (excluding) |
| Golang-go.crypto | Ubuntu | esm-apps/focal | * |
| Golang-go.crypto | Ubuntu | esm-apps/jammy | * |
| Golang-go.crypto | Ubuntu | esm-apps/noble | * |
| Golang-go.crypto | Ubuntu | esm-apps/resolute | * |
| Golang-go.crypto | Ubuntu | jammy | * |
| Golang-go.crypto | Ubuntu | noble | * |
| Golang-go.crypto | Ubuntu | questing | * |
| Golang-go.crypto | Ubuntu | resolute | * |
| Golang-go.crypto | Ubuntu | upstream | * |
| Google-guest-agent | Ubuntu | devel | * |
| Google-guest-agent | Ubuntu | esm-apps-legacy/xenial | * |
| Google-guest-agent | Ubuntu | esm-apps/bionic | * |
| Google-guest-agent | Ubuntu | esm-infra/focal | * |
| Google-guest-agent | Ubuntu | jammy | * |
| Google-guest-agent | Ubuntu | noble | * |
| Google-guest-agent | Ubuntu | questing | * |
| Google-guest-agent | Ubuntu | resolute | * |
| Lxd | Ubuntu | esm-infra-legacy/xenial | * |
| Lxd | Ubuntu | esm-infra/bionic | * |