Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A critical authentication bypass vulnerability (CVSS 10.0) in the Go cryptography library’s SSH implementation allows an attacker to bypass public key authentication controls entirely when the VerifiedPublicKeyCallback mechanism is invoked. The affected component is Microsoft’s azl3 docker-buildx 0.14.0-11 package on Azure Linux 3.0, used in container build infrastructure. Organizations running this package in CI/CD or container build pipelines are exposed to unauthorized access to build systems, with potential for supply chain compromise.

Author

Tech Jacks Solutions