Description
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0369 | Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride. |
Github GHSA |
GHSA-573x-jhqh-jg36 | Improper Certificate Validation in chloride |
References
| Link | Providers |
|---|---|
| https://puppet.com/security/cve/CVE-2018-6517 |
|
History
No history.
Status: PUBLISHED
Assigner: puppet
Published:
Updated: 2024-08-05T06:10:10.019Z
Reserved: 2018-02-01T00:00:00.000Z
Link: CVE-2018-6517
No data.
Status : Modified
Published: 2019-03-21T16:00:56.483
Modified: 2024-11-21T04:10:48.843
Link: CVE-2018-6517
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA