Aria Operations for Logs 8.14 and later
Many vulnerability scanners will not do a proper penetration test, instead they will check the major version of the packages. We do not typically use the newest version of the packages, as there is an ecosystem in place and upgrading some packages can have a knock on affect with other packages that are installed. When a CVE vulnerability is found we will usually apply a fix to the package but the major version of the package will remain the same.
CVE 2023-38408 is addressed for Photon OS 4.0 in 8.9p1-1.ph4 version of Openssh package. Openssh package was updated to 8.9p1-1.ph4 in Aria Operations for Logs 8.14 so 8.14.x and later is not affected.
CVE CVE-2024-6387 is addressed in Photon OS 4.0 8.9p1-8.ph4. Openssh package 8.9p1-8.ph4 is updated to 8.9p1-8.ph4 in Aria Operations for Logs 8.18 hot fix 1 , so 8.18 hf 1 or later is not affected. This is mentioned in the release notes for Aria Operations for Logs Hot Fix 1 found here.
cat /etc/photon-release
rpm -qa | grep openssh
*Note before upgrading/applying hot fix please ensure you take snapshots of all nodes in the cluster.