Information Exposure Affecting awx package, versions <24.6.1-r33


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.99% (59th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-AWX-15989995
  • published12 Apr 2026
  • disclosed23 Jan 2024

Introduced: 23 Jan 2024

CVE-2024-23342  (opens in a new tab)
CWE-203  (opens in a new tab)
CWE-208  (opens in a new tab)
CWE-385  (opens in a new tab)

How to fix?

Upgrade Chainguard awx to version 24.6.1-r33 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream awx package and not the awx package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

The ecdsa PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.

CVSS Base Scores

version 3.1