summaryrefslogtreecommitdiffstats
path: root/changelogs/fragments/user_ssh_fix.yml
blob: b2c47d60e3a995e152de8c176dfc93e978fd1c92 (plain)
1
2
3
4
bugfixes:
  - user action will now require O(force) to overwrite the public part of an ssh key when generating ssh keys, as was already the case for the private part.
security_fixes:
  - user action won't allow ssh-keygen, chown and chmod to run on existing ssh public key file, avoiding traversal on existing symlinks (CVE-2024-9902).