CVE-2018-6517: Improper Certificate Validation
(updated )
Chloride’s use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user’s known_hosts
file without confirmation.
References
Detect and mitigate CVE-2018-6517 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →