Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade amazon-cloudwatch-agentUpgrade containerdUpgrade containerd-stressUpgrade docker-debuginfoUpgrade containerd-debuginfoUpgrade dockerUpgrade nerdctl-debuginfoUpgrade nerdctlUpgrade runfinch-finch | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade rclone-debuginfoUpgrade docker-debugsourceUpgrade runfinch-finchUpgrade containerd-stressUpgrade rclone-debugsourceUpgrade dockerUpgrade containerd-stress-debuginfoUpgrade containerd-debugsourceUpgrade containerdUpgrade docker-debuginfoUpgrade nerdctlUpgrade rcloneUpgrade amazon-cloudwatch-agentUpgrade containerd-debuginfo | Jun 9, 2026 | May 22, 2026 |
| Redhat_linux | — | Upgrade flightctl-cliUpgrade flightctl-observabilityUpgrade flightctl-agentNo solution existsUpgrade flightctl-servicesUpgrade flightctl-selinux | Jul 17, 2026 | May 22, 2026 |
| Ubuntu | — | Upgrade golang-golang-x-crypto-dev (Ubuntu Pro)Upgrade google-guest-agent | Jun 18, 2026 | Jun 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub