-
-
Notifications
You must be signed in to change notification settings - Fork 18.3k
Closed
Description
Right now litestream is marked as vulnerable because of CVE-2024-41254 (The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.)
There are 2 patches for that available which implement ssh host key pinning
If these patches don't break existing setups then IMO it would be a good idea to include them and remove the vulnerability from meta.
CC @cideM
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels