4 findings
Vulnerabilities
CVE-2024-45337
Authorization bypass in applications using x/crypto/ssh
Published 11 Dec 2024 View advisory ↗
High Not deployed
Executive summary
No production impact identifiedThe vulnerable package is present in the checkout-api component, but the application does not use ssh.ServerConfig.PublicKeyCallback. No production impact was identified for the detected usage.
Last analysed 2 minutes ago
Impact scope
1 affected component · 0 environments
Affected components
checkout-api
Container image · checkout:72bc81
Matched package
golang.org/x/crypto@v0.30.0
Affected environments
No connected environment
The affected component is inventoried but is not deployed to Production or Staging.
Detected package
golang.org/x/crypto@v0.30.0
Fixed version
v0.31.0
Match confidence
Confirmed inventory
Component and environment evidence
01 · Component
checkout-api
checkout:72bc81
Container image · contains golang.org/x/crypto@v0.30.0
02 · Environment
ECS · checkout-prod
internal-checkout.northstar.test