| id: GO-2025-3649 |
| modules: |
| - module: github.com/rancher/fleet |
| versions: |
| - introduced: 0.9.0-rc.1 |
| - fixed: 0.10.12 |
| - introduced: 0.11.0 |
| - fixed: 0.11.7 |
| - introduced: 0.12.0 |
| - fixed: 0.12.2 |
| vulnerable_at: 0.12.1 |
| summary: Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet |
| cves: |
| - CVE-2025-23390 |
| ghsas: |
| - GHSA-xgpc-q899-67p8 |
| references: |
| - advisory: https://github.com/rancher/fleet/security/advisories/GHSA-xgpc-q899-67p8 |
| - fix: https://github.com/rancher/fleet/pull/3571 |
| - fix: https://github.com/rancher/fleet/pull/3572 |
| - fix: https://github.com/rancher/fleet/pull/3573 |
| - web: https://github.com/rancher/fleet/releases/tag/v0.10.12 |
| - web: https://github.com/rancher/fleet/releases/tag/v0.11.7 |
| - web: https://github.com/rancher/fleet/releases/tag/v0.12.2 |
| source: |
| id: GHSA-xgpc-q899-67p8 |
| created: 2025-04-29T12:46:49.563239-04:00 |
| review_status: UNREVIEWED |