net-ssh is vulnerable to Denial of Service (DoS)
53
Medium Risk
Net::SSH::KeyFactory.load_data_private_key parses OpenSSH private keys through bcrypt_pbkdf without bounding the number of key derivation rounds encoded in the key file. A crafted key with an extreme round count locks the process in CPU bound derivation for an effectively unbounded time, even though the file is not a valid SSH key.
You are affected if you are using a version that falls within the vulnerable range and you load a private key file from an untrusted source.
net-ssh is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.3.4.
Upgrade the net-ssh library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.