CVE-2024-45337
CriticalAdvisory
Published 11 Dec 2024In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,576
- of 17,797 indexed, latest versions
- Container images
- 1,828
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
Carried by container images the latest versions of 1,576 of 17,797 indexed charts deploy, on 1,828 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+134 more | 0.31.0 | 1,828 |
- OSV records
- GHSA-v778-237x-gjrc
- Also known as
- GO-2024-3321
Charts affected
1,576 by stars
Container images carrying it
1,828 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | ec36422b09af | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 42574f512837 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 9518de37eed5 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e24894e32cbc | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 49b1c312e342 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | aa0c8526ae5e | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | a1d4cf8b8fe1 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e3d1f1302e49 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ac8459f70f85 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | af77073c184f | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 05aa441b20aa | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 8324bbc0ec08 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 669e27a5d1af | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | c6fe64c7bfcd | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 6bf945565865 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 313edfec2fca | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 00ce11c31087 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 087618d16b83 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 8e7b44bbd123 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 5e409a6332b4 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 06ed5db6cd33 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | b914032ef9ad | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 9c73f1841ebc | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | a61c7022abcf | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 832a32779e6d | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 185d2eebc60c | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 63f7eaf5aa8a | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | c62e3347611c | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 89028adefcff | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 6650119a385f | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e459ad3ae758 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | d523c2c010cd | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 23dc6274cc4b | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 0b2a41c2a43e | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | a792931146b4 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 528f2174fa2f | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | b3256cbc7b68 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 5c109914ff73 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | fa6dba122171 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 5dfa86b6451f | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | b69bcdaa8492 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 84f70425f4dd | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 45e744fc623f | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | ded797477896 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | fa1f6b2e9a6e | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | df917c5a7e54 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 7fbc6855c8b3 | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 3267d27d392f | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | 7ffcb25b4cfc | golang.org/ | 0.31.0 | 1 |
| ghcr.io/ | e949b0f733f0 | golang.org/ | 0.31.0 | 1 |