CVE-2024-37370 Affecting krb5 package, versions <1.20.2-r1
Threat Intelligence
EPSS
0.09% (39th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALPINE318-KRB5-8366393
- published 11 Nov 2024
- disclosed 28 Jun 2024
Introduced: 28 Jun 2024
CVE-2024-37370 Open this link in a new tabHow to fix?
Upgrade Alpine:3.18
krb5
to version 1.20.2-r1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream krb5
package and not the krb5
package as distributed by Alpine
.
See How to fix?
for Alpine:3.18
relevant fixed versions and status.
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
CVSS Scores
version 3.1