blob: af5f73c178d2ce9b92d70459246fba358572d72a [file] [log] [blame]
id: GO-2025-3649
modules:
- module: github.com/rancher/fleet
versions:
- introduced: 0.9.0-rc.1
- fixed: 0.10.12
- introduced: 0.11.0
- fixed: 0.11.7
- introduced: 0.12.0
- fixed: 0.12.2
vulnerable_at: 0.12.1
summary: Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet
cves:
- CVE-2025-23390
ghsas:
- GHSA-xgpc-q899-67p8
references:
- advisory: https://github.com/rancher/fleet/security/advisories/GHSA-xgpc-q899-67p8
- fix: https://github.com/rancher/fleet/pull/3571
- fix: https://github.com/rancher/fleet/pull/3572
- fix: https://github.com/rancher/fleet/pull/3573
- web: https://github.com/rancher/fleet/releases/tag/v0.10.12
- web: https://github.com/rancher/fleet/releases/tag/v0.11.7
- web: https://github.com/rancher/fleet/releases/tag/v0.12.2
source:
id: GHSA-xgpc-q899-67p8
created: 2025-04-29T12:46:49.563239-04:00
review_status: UNREVIEWED