An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
| Software | From | Fixed in |
|---|---|---|
github.com/casdoor/casdoor
|
1.541.0 | 1.636.0.x |
| casbin / casdoor | 1.636.0 | 1.636.0.x |