CVE-2024-21653
vantage6 has insecure SSH configuration for node and server containers
6.5
MEDIUM
CVSS 3.1
EPSS 0.47%
描述
### Impact Nodes and servers get a ssh config by default that permits root login with password authentication. In a proper deployment, the SSH service is not exposed so there is no risk, but not all deployments are ideal. The default should therefore be less permissive. We will probably opt to completely remove the ssh option as it is only used for debugging. Later, we can add a debug mode where we can activate it if necessary. ### Workarounds Remove the ssh part from the docker file and build your own docker image
如何修補 CVE-2024-21653
要修補 CVE-2024-21653,請將受影響套件升級到下列已修補版本。
- —升級至 4.2.0 或更新版本
- —升級至 4.2.0 或更新版本
- —升級至 3fcc6e6a8bd1142fd7a558d8fdd2b246e55c8841 或更新版本
- —升級至 3fcc6e6a8bd1142fd7a558d8fdd2b246e55c8841 或更新版本
CVE-2024-21653 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 4.2.0
- from 0, < 4.2.0
- from 0, < 3fcc6e6a8bd1142fd7a558d8fdd2b246e55c8841 | from 0, < 4.2.0
- from 0, < 3fcc6e6a8bd1142fd7a558d8fdd2b246e55c8841 | from 0, < 4.2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |