CVE-2024-39223
Critical
Missing key verification in gost in github.com/ginuerzh/gost
Missing key verification in gost in github.com/ginuerzh/gost
Exploit probability
0.7%
Published
October 28, 2024
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-3224
View original source
Missing key verification in gost in github.com/ginuerzh/gost
Open Source Vulnerabilities
GHSA-8wxx-35qc-vp6r
View original source
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
05 / REFERENCES
Further evidence
- https://gist.github.com/nyxfqq/a7242170b1118e78436a62dee4e09e8a
- https://github.com/advisories/GHSA-8wxx-35qc-vp6r
- https://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229
- https://github.com/ginuerzh/gost/issues/1034
- https://nvd.nist.gov/vuln/detail/CVE-2024-39223
- https://github.com/ginuerzh/gost