summaryrefslogtreecommitdiffstats
path: root/changelogs/fragments/user_ssh_fix.yml
diff options
context:
space:
mode:
Diffstat (limited to 'changelogs/fragments/user_ssh_fix.yml')
-rw-r--r--changelogs/fragments/user_ssh_fix.yml4
1 files changed, 4 insertions, 0 deletions
diff --git a/changelogs/fragments/user_ssh_fix.yml b/changelogs/fragments/user_ssh_fix.yml
new file mode 100644
index 0000000000..b2c47d60e3
--- /dev/null
+++ b/changelogs/fragments/user_ssh_fix.yml
@@ -0,0 +1,4 @@
+bugfixes:
+ - user action will now require O(force) to overwrite the public part of an ssh key when generating ssh keys, as was already the case for the private part.
+security_fixes:
+ - user action won't allow ssh-keygen, chown and chmod to run on existing ssh public key file, avoiding traversal on existing symlinks (CVE-2024-9902).