Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade runfinch-finchUpgrade nerdctlUpgrade docker-debuginfoUpgrade dockerUpgrade amazon-cloudwatch-agentUpgrade nerdctl-debuginfoUpgrade containerdUpgrade containerd-stressUpgrade containerd-debuginfo | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade containerd-debugsourceUpgrade docker-debuginfoUpgrade containerd-stress-debuginfoUpgrade dockerUpgrade amazon-cloudwatch-agentUpgrade containerd-debuginfoUpgrade containerdUpgrade nerdctlUpgrade rcloneUpgrade rclone-debugsourceUpgrade runfinch-finchUpgrade docker-debugsourceUpgrade rclone-debuginfoUpgrade containerd-stress | Jun 9, 2026 | May 22, 2026 |
| Redhat_linux | — | Upgrade flightctl-servicesNo solution existsUpgrade flightctl-selinuxUpgrade flightctl-observabilityUpgrade flightctl-agentUpgrade flightctl-cli | Jul 17, 2026 | May 22, 2026 |
| Ubuntu | — | Upgrade golang-golang-x-crypto-dev (Ubuntu Pro)Upgrade google-guest-agent | Jun 18, 2026 | Jun 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub