Uploaded image for project: 'FUSE Mediation Router'
  1. FUSE Mediation Router
  2. MR-107

Camel SFTP not performing host key verification

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Critical
    • 1.5.2.0-fuse
    • 1.4.3.0-fuse
    • None
    • None

    Description

      Camel fails to verify the host key against the known-hosts file and continues its communication with the remote server. This makes the users vulnerable to MIM (man in the middle attack) and it is inconsistent with intended safeguards of SSH.

      Attachments

        1. patch.tar.gz
          1 kB
          Dave Stanley
        2. testcase.tar.gz
          214 kB
          Dave Stanley

        Activity

          People

            janstey@redhat.com Jonathan Anstey
            davestanley Dave Stanley (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: