wolfSSL.wolfssh is vulnerable to Improper Authentication
94
Critical Risk
A malicious server can bypass the client’s host verification, potentially exposing client credentials. This issue affects client applications using wolfSSH version 1.4.20 and earlier. Client-side users of wolfSSH should update to a fixed version or apply the provided patch, and it is recommended to rotate any credentials that may have been exposed.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssh is vulnerable to Improper Authentication in versions 0.0.1 - 1.4.20.
Upgrade the wolfSSL.wolfssh library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant