296,733
Total vulnerabilities in the database
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.
| Software | From | Fixed in |
|---|---|---|
| golang / crypto | - | 2017-03-17.x |
golang.org/x/crypto
|
- | 0.0.0-20170330155735-e4e2799dd7aa |