Skip to content

Include patches for SSH host key check in litestream #388411

@surfaceflinger

Description

@surfaceflinger

Right now litestream is marked as vulnerable because of CVE-2024-41254 (The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.)

There are 2 patches for that available which implement ssh host key pinning

If these patches don't break existing setups then IMO it would be a good idea to include them and remove the vulnerability from meta.

CC @cideM

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions