CVE-2024-45337
CriticalAdvisory
Published 11 Dec 2024In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,579
- of 17,790 indexed, latest versions
- Container images
- 1,831
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
Carried by container images the latest versions of 1,579 of 17,790 indexed charts deploy, on 1,831 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+134 more | 0.31.0 | 1,831 |
- OSV records
- GHSA-v778-237x-gjrc
- Also known as
- GO-2024-3321
Charts affected
1,579 by stars
Container images carrying it
1,831 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| engrmth/ | 6d8464e6f0e8 | golang.org/ | 0.31.0 | 1 |
| envoyproxy/ | 71081616da3e | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 90f9921d8d58 | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 96028c86f0dd | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 616c678ba3e7 | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 976a662a5e72 | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 93417e18bb1a | golang.org/ | 0.31.0 | 1 |
| epamedp/ | b71fb39e0c9e | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 28ef56bc0ca3 | golang.org/ | 0.31.0 | 1 |
| epamedp/ | ff25e9fe4419 | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 5d352199e12e | golang.org/ | 0.31.0 | 1 |
| epamedp/ | 449a53804699 | golang.org/ | 0.31.0 | 1 |
| epamedp/ | d33e938b6d59 | golang.org/ | 0.31.0 | 1 |
| erenozcan17/ | 50b4f23422b6 | golang.org/ | 0.31.0 | 1 |
| etejeda/ | 737d58183abc | golang.org/ | 0.31.0 | 1 |
| ethereum/ | 6d6d12a40465 | golang.org/ | 0.31.0 | 1 |
| ethereum/ | 886ec69b35b0 | golang.org/ | 0.31.0 | 1 |
| ethereum/ | cce21b423165 | golang.org/ | 0.31.0 | 1 |
| ethereum/ | d99fbb9585c7 | golang.org/ | 0.31.0 | 1 |
| ethereumoptimism/ | 5577036dc36d | golang.org/ | 0.31.0 | 1 |
| ethersphere/ | a884fd84b72f | golang.org/ | 0.31.0 | 1 |
| ethersphere/ | 513154aab230 | golang.org/ | 0.31.0 | 1 |
| ethpandaops/ | 1a9c3264f0a9 | golang.org/ | 0.31.0 | 1 |
| ethpandaops/ | ad26158420dd | golang.org/ | 0.31.0 | 1 |
| ethpandaops/ | e261d1734e9f | golang.org/ | 0.31.0 | 1 |
| ethpandaops/ | d1780db2e286 | golang.org/ | 0.31.0 | 1 |
| everpcpc/ | b378d137ae8b | golang.org/ | 0.31.0 | 1 |
| factly/ | 66fafc7b0a17 | golang.org/ | 0.31.0 | 1 |
| factly/ | 94d21479382e | golang.org/ | 0.31.0 | 1 |
| factly/ | be85ff1b9bd3 | golang.org/ | 0.31.0 | 1 |
| factly/ | 384d384310ef | golang.org/ | 0.31.0 | 1 |
| factly/ | 87064eb0463c | golang.org/ | 0.31.0 | 1 |
| falcosecurity/ | 828ee36cb13a | golang.org/ | 0.31.0 | 1 |
| feiyu563/ | 224cfa68cbd9 | golang.org/ | 0.31.0 | 1 |
| filebrowser/ | 4fcd47af573c | golang.org/ | 0.31.0 | 1 |
| filebrowser/ | c5d0a75a0041 | golang.org/ | 0.31.0 | 1 |
| fission/ | 3fcfd8a0fa5d | golang.org/ | 0.31.0 | 1 |
| fission/ | fa0f24cdb9cd | golang.org/ | 0.31.0 | 1 |
| flanksource/ | 1dacc3195bf9 | golang.org/ | 0.31.0 | 1 |
| flashbots/ | 7c486b5789da | golang.org/ | 0.31.0 | 1 |
| flomesh/ | cc39c96711c4 | golang.org/ | 0.31.0 | 1 |
| flomesh/ | 22f849c70b25 | golang.org/ | 0.31.0 | 1 |
| flomesh/ | b188e128cbfe | golang.org/ | 0.31.0 | 1 |
| flomesh/ | add7a4da4622 | golang.org/ | 0.31.0 | 1 |
| flomesh/ | 47287e3ad324 | golang.org/ | 0.31.0 | 1 |
| fluxcd/ | 92b891e495d8 | golang.org/ | 0.31.0 | 1 |
| fluxcd/ | 31a8c79a6803 | golang.org/ | 0.31.0 | 1 |
| fluxninja/ | 356d7aa86632 | golang.org/ | 0.31.0 | 1 |
| foxcpp/ | 6ab538e2f28b | golang.org/ | 0.31.0 | 1 |
| foxcpp/ | 8fa2bd8f6830 | golang.org/ | 0.31.0 | 1 |