tomaswolf commented on issue #311:
URL: https://github.com/apache/mina-sshd/issues/311#issuecomment-1384457928

   We wrote in the [CVE 
announcement](https://www.mail-archive.com/users@mina.apache.org/msg06948.html),
 also [linked at the 
NIST](https://www.mail-archive.com/dev@mina.apache.org/msg39312.html), that all 
versions <= 2.9.1 were affected. We also gave steps how to mitigate the 
vulnerability. Beyond that, I cannot give any further advice. I don't have the 
time to analyze v2.7.0 to see if that version might use it even if you set a 
different key provider. In current master code, there is exactly one place in 
non-test code where the SimpleGeneratorHostKeyProvider is used. (In 
SshServerCliSupport.resolveServerKeys().)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@mina.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@mina.apache.org
For additional commands, e-mail: dev-h...@mina.apache.org

Reply via email to