-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
All three functions in viaSSHDialer.go configure SSH clients with HostKeyCallback: ssh.InsecureIgnoreHostKey(), which explicitly disables host key verification. This violates secure SSH practices by allowing potential MITM attacks, directly enabling the CWE-295/297 certificate validation flaws and CWE-200 information exposure described in the advisory. The code references match exactly with the vulnerability reports and GitHub file links provided.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/casdoor/casdoor | go | >= 1.541.0, <= 1.636.0 |
Ongoing coverage of React2Shell