[go: up one dir, main page]

Skip to content

terrapin ssh vulnerability

According to terrapin the ssh deamon offered by gitlab is vulnerable for terrapin attacks (part of on prem gitlab installations)

terrapin recommends to disable a cipher but i see no option how this can be done with the gitlab go ssh daemon.

example config line that can be added to openssh for mitigation:

#CVE-2023-48795 mitigation
Ciphers -chacha20-poly1305@openssh.com

gitlab version I checked: 16.5.4-ce0

steps to reprduce:

references:

Edited by 🤖 GitLab Bot 🤖