---
title: NR24-02 - OpenSSH in New Relic Salesforce Exporter
source: https://docs.newrelic.com/docs/security/new-relic-security/security-bulletins/security-bulletin-nr24-02
---

**Vulnerability Identifier:** NR24-02

**Priority:** High

## Summary

New Relic advises all customers using the New Relic Salesforce Exporter to update to version 2.2.0, which New Relic has released to eliminate a recently announced [vulnerable version of OpenSSH](https://nvd.nist.gov/vuln/detail/CVE-2024-6387).

## Action required

New Relic is recommending that customers who use the New Relic Salesforce Exporter immediately update to version 2.2.0.

New Relic has provided the following resources to assist with these updates:

-   [Salesforce Exporter Release Notes](https://github.com/newrelic/newrelic-salesforce-exporter/releases/tag/2.2.0)
-   [Detecting & Upgrading on-host deployments](https://github.com/newrelic/newrelic-salesforce-exporter?tab=readme-ov-file#upgrading-on-host-deployments)

If customers are unable to upgrade their New Relic Salesforce Exporter, limit SSH access through network-based controls to minimize the attack risks.

## Supporting Release Notes

[Salesforce Exporter Release Notes](https://github.com/newrelic/newrelic-salesforce-exporter/releases/tag/2.2.0)

## Technical vulnerability information

[CVE-2024-6387](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387)

## Publication History

July 18, 2024 - NR24-02 Published
