CVE-2024-45337
CriticalAdvisory
Published 11 Dec 2024In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,577
- of 17,792 indexed, latest versions
- Container images
- 1,829
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
Carried by container images the latest versions of 1,577 of 17,792 indexed charts deploy, on 1,829 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+134 more | 0.31.0 | 1,829 |
- OSV records
- GHSA-v778-237x-gjrc
- Also known as
- GO-2024-3321
Charts affected
1,577 by stars
Container images carrying it
1,829 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | deed102b4255 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 35225eaa87ab | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 4ffe222b3e3a | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 26d91dcbba56 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 834b8e1af290 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 72aae2080595 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 1ea5412bed26 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ef77f4c089a1 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | cd9656e6bc2c | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | c22764cbfa97 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | d17257e4fa27 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 956c4fb64796 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 7242da105081 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | eb36ead1954e | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | afe623824b82 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 04f1b7f0d573 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | f745e2870692 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 198db44fabb5 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 66bbaf95a123 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e918014fb8d3 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | c4f6c03af5d3 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 64f5eb7a398b | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | f36c423cd259 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | b2666ffcbad8 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 9affab218351 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 8f1bbd5cda85 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 8c7fa5552028 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 6a1c4a81a924 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e37d61b5277c | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ee1eb3c9c9a1 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | f9de3a1a5deb | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ff0cd9db78d3 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 19b18fd97eab | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 13964b29d63e | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | f579d00721b0 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | b360d44125ad | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | a43323732181 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 1041d4449e49 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 6b3215e37738 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 627e5e211766 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ec06685b9ff4 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 073116e61007 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | bcd5b8d4c45c | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ab3f7d0a1d50 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | d3de52dfb0b4 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 2f5be9cde5f9 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 56a1ea4490ba | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e3552fa0c68a | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ab40c1745534 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 923a3f704b21 | golang.org/ | 0.31.0 | 1 |