Closed ghost closed 2 years ago
Hi there,
Thanks for your report but I don't use golang.org/x/crypto
as a direct dependency ie; as something exposed to users that can be exploited.
The exploit mentioned is around being ssh signature verifcation. khinsider doesn't deal with ssh keys, directly or indirectly.
检测到 marcus-crane/khinsider 一共引入了39个开源组件,存在3个漏洞
另外还有3个漏洞,详细报告:https://mofeisec.com/jr?p=a8693e