CVE-2024-45337
CriticalAdvisory
Published 11 Dec 2024In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,579
- of 17,790 indexed, latest versions
- Container images
- 1,831
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
Carried by container images the latest versions of 1,579 of 17,790 indexed charts deploy, on 1,831 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+134 more | 0.31.0 | 1,831 |
- OSV records
- GHSA-v778-237x-gjrc
- Also known as
- GO-2024-3321
Charts affected
1,579 by stars
Container images carrying it
1,831 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| prom/ | 4e4cfd809e96 | golang.org/ | 0.31.0 | 1 |
| prom/ | e54bca6645ea | golang.org/ | 0.31.0 | 1 |
| prom/ | 01267317c95d | golang.org/ | 0.31.0 | 1 |
| prom/ | bb01ad25e9fc | golang.org/ | 0.31.0 | 1 |
| prom/ | d2e48098c364 | golang.org/ | 0.31.0 | 1 |
| prom/ | 4f6c47e39a90 | golang.org/ | 0.31.0 | 1 |
| prom/ | 5880ec936055 | golang.org/ | 0.31.0 | 1 |
| prom/ | b440bc0e8aa5 | golang.org/ | 0.31.0 | 1 |
| prom/ | cd134bd4fca0 | golang.org/ | 0.31.0 | 1 |
| prom/ | e4ca62c0d62f | golang.org/ | 0.31.0 | 1 |
| prom/ | f7ffebdd428b | golang.org/ | 0.31.0 | 1 |
| prom/ | 28fe26c8b8b1 | golang.org/ | 0.31.0 | 1 |
| prom/ | 3496e0f85943 | golang.org/ | 0.31.0 | 1 |
| prom/ | 9d226d7de223 | golang.org/ | 0.31.0 | 1 |
| prom/ | 61d866e93b56 | golang.org/ | 0.31.0 | 1 |
| pschiffe/ | 37ebba8c2b8f | golang.org/ | 0.31.0 | 1 |
| pschiffe/ | d196c796cafb | golang.org/ | 0.31.0 | 1 |
| pschiffe/ | a227d41bc665 | golang.org/ | 0.31.0 | 1 |
| qmcgaw/ | 2b42bfa04675 | golang.org/ | 0.31.0 | 1 |
| qonstrukt/ | 089af7925aa1 | golang.org/ | 0.31.0 | 1 |
| quiq/ | 91281da47036 | golang.org/ | 0.31.0 | 1 |
| rabbitmqoperator/ | 231e7ce0e905 | golang.org/ | 0.31.0 | 1 |
| rancher/ | 6d2cd61a338b | golang.org/ | 0.31.0 | 1 |
| rancher/ | c678c25d47c8 | golang.org/ | 0.31.0 | 1 |
| rancher/ | 42784bb38ed3 | golang.org/ | 0.31.0 | 1 |
| rancher/ | d6a47d394c03 | golang.org/ | 0.31.0 | 1 |
| rancher/ | 8eb8092f0728 | golang.org/ | 0.31.0 | 1 |
| rancher/ | 8c2599ecfca8 | golang.org/ | 0.31.0 | 1 |
| rancher/ | eaa270df79cc | golang.org/ | 0.31.0 | 1 |
| rancher/ | 85a0d1148784 | golang.org/ | 0.31.0 | 1 |
| rancher/ | 9b9148811700 | golang.org/ | 0.31.0 | 1 |
| rancher/ | d5999b20a1b1 | golang.org/ | 0.31.0 | 1 |
| rancher/ | e34c88ae0aff | golang.org/ | 0.31.0 | 1 |
| rancher/ | febfd0517838 | golang.org/ | 0.31.0 | 1 |
| rclone/ | 08e1af3c8814 | golang.org/ | 0.31.0 | 1 |
| rclone/ | 1e6eeabddc01 | golang.org/ | 0.31.0 | 1 |
| rclone/ | f2fc45c8bc57 | golang.org/ | 0.31.0 | 1 |
| reaper99/ | 7f7ec3aeb88c | golang.org/ | 0.31.0 | 1 |
| replicated/ | 8751b4963250 | golang.org/ | 0.31.0 | 1 |
| reportportal/ | da5d8e1395fe | golang.org/ | 0.31.0 | 1 |
| reportportal/ | 2b27a2d7a87d | golang.org/ | 0.31.0 | 1 |
| restic/ | 579e4e6a4931 | golang.org/ | 0.31.0 | 1 |
| rezachalak/ | 34f694325191 | golang.org/ | 0.31.0 | 1 |
| robotshop/ | 119b545823cd | golang.org/ | 0.31.0 | 1 |
| robustadev/ | 0457a51e36e8 | golang.org/ | 0.31.0 | 1 |
| rokk42/ | dfc850a5db9e | golang.org/ | 0.31.0 | 1 |
| rookout/ | 0d083f3ef1a7 | golang.org/ | 0.31.0 | 1 |
| rss3/ | e8adc09d9c07 | golang.org/ | 0.31.0 | 1 |
| rss3/ | 45b91380bbe7 | golang.org/ | 0.31.0 | 1 |
| rss3/ | 96672897ba9e | golang.org/ | 0.31.0 | 1 |