vulnerability

Amazon Linux AMI: CVE-2024-24790: Security patch for amazon-ssm-agent (ALAS-2024-1948)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 5, 2024
Added
Oct 4, 2024
Modified
May 21, 2025

Description

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Solution

amazon-linux-upgrade-amazon-ssm-agent
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.