Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.4 release
Red Hat build of OpenTelemetry is a collection of tools, APIs, and SDKs. You use it to instrument, generate, collect, and export telemetry data (metrics, logs, and traces) for analysis in order to understand your software's performance and behavior.
AI Analysis
Technical Summary
The vulnerability CVE-2024-45337 exists in the golang.org/x/crypto/ssh library's ServerConfig.PublicKeyCallback function. Applications that misuse this callback may incorrectly authorize users by making decisions based on a public key for which the attacker does not hold the private key. The issue arises because PublicKeyCallback may be called multiple times with different keys during SSH authentication, and improper handling can lead to authorization bypass. Red Hat OpenShift Container Platform 4.14 is affected, and a security update in version 4.14.57 fixes this flaw. The vulnerability is rated as important (high severity) because it depends on insecure application logic to be exploitable and does not directly grant unauthorized access.
Potential Impact
An attacker could potentially bypass authorization checks in applications that misuse the ServerConfig.PublicKeyCallback API during SSH authentication. This could lead to unauthorized access or privilege escalation if the application makes authorization decisions based on an incorrect public key. The vulnerability impacts confidentiality and integrity by allowing unauthorized reading or modification of sensitive data. However, properly implemented systems that do not rely on this callback or use the Permissions field correctly are not affected. Red Hat Enterprise Linux 8 & 9 and some other Red Hat products are not affected as they do not call this function.
Mitigation Recommendations
Red Hat has released OpenShift Container Platform 4.14.57 which includes a fix for this vulnerability. Users of OpenShift Container Platform 4.14 are strongly advised to upgrade to version 4.14.57 or later to remediate this issue. No other effective mitigations meeting Red Hat's criteria are currently available. Systems that do not misuse the PublicKeyCallback API are not vulnerable. Follow Red Hat's official upgrade instructions using the OpenShift CLI or web console to apply the update.
Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.4 release
Description
Red Hat build of OpenTelemetry is a collection of tools, APIs, and SDKs. You use it to instrument, generate, collect, and export telemetry data (metrics, logs, and traces) for analysis in order to understand your software's performance and behavior.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2024-45337 exists in the golang.org/x/crypto/ssh library's ServerConfig.PublicKeyCallback function. Applications that misuse this callback may incorrectly authorize users by making decisions based on a public key for which the attacker does not hold the private key. The issue arises because PublicKeyCallback may be called multiple times with different keys during SSH authentication, and improper handling can lead to authorization bypass. Red Hat OpenShift Container Platform 4.14 is affected, and a security update in version 4.14.57 fixes this flaw. The vulnerability is rated as important (high severity) because it depends on insecure application logic to be exploitable and does not directly grant unauthorized access.
Potential Impact
An attacker could potentially bypass authorization checks in applications that misuse the ServerConfig.PublicKeyCallback API during SSH authentication. This could lead to unauthorized access or privilege escalation if the application makes authorization decisions based on an incorrect public key. The vulnerability impacts confidentiality and integrity by allowing unauthorized reading or modification of sensitive data. However, properly implemented systems that do not rely on this callback or use the Permissions field correctly are not affected. Red Hat Enterprise Linux 8 & 9 and some other Red Hat products are not affected as they do not call this function.
Mitigation Recommendations
Red Hat has released OpenShift Container Platform 4.14.57 which includes a fix for this vulnerability. Users of OpenShift Container Platform 4.14 are strongly advised to upgrade to version 4.14.57 or later to remediate this issue. No other effective mitigations meeting Red Hat's criteria are currently available. Systems that do not misuse the PublicKeyCallback API are not vulnerable. Follow Red Hat's official upgrade instructions using the OpenShift CLI or web console to apply the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:16165
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-22869"]
Threat ID: 6a160975e29bf47b506400de
Added to database: 05/26/2026, 20:58:29 UTC
Last enriched: 08/14/2026, 23:18:14 UTC
Last updated: 09/10/2026, 20:00:15 UTC
Views: 116
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.