CVE-2020-9283: Improper Verification of Cryptographic Signature
(updated )
golang.org/x/crypto
allows a panic during signature verification in the golang.org/x/crypto/ssh
package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.
References
Detect and mitigate CVE-2020-9283 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →