passbolt Helm chart
cniegScored 14 Sept 2026
A Helm chart to deploy Passbolt
Latest 1.1.17 3 years agoapp version 3.4.0-ce-non-root 4Artifact Hub
passbolt 1.1.17 deploys 2 container images: passbolt/passbolt and bitnami/mariadb. Across the 1 measured, 284 findings — 1 critical, 5 high — 4 on CISA KEV. The highest contribution is DEBIAN-CVE-2022-31626 in php7.4 7.4.25-1+deb11u1, fixed in 7.4.30-1+deb11u1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| passbolt/ | 3.4.0-ce-non-root | 1543235 | 3,543 |
| bitnami/ | 10.11.3-debian-11-r5 | — | unmeasured |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | DEBIAN-CVE-2022-31626 | php7.4 | 7.4.30-1+deb11u1 |
| High | DEBIAN-CVE-2022-31629 | php7.4 | 7.4.33-1+deb11u1 |
| High | DLA-4104-1KEV | freetype | 2.10.4+dfsg-1+deb11u2 |
| High | DSA-5497-2KEV | libwebp | 0.6.1-2.1+deb11u2 |
| High | DSA-5514-1KEV | glibc | 2.31-13+deb11u7 |
| High | DSA-5570-1KEV | nghttp2 | 1.43.0-1+deb11u1 |
| Medium | DLA-3859-1 | systemd | 247.3-7+deb11u6 |
| Medium | DSA-5169-1 | openssl | 1.1.1n-0+deb11u3 |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | DSA-5673-1 | glibc | 2.31-13+deb11u9 |
| Medium | DLA-3898-1 | nghttp2 | 1.43.0-1+deb11u2 |
| Medium | DSA-5139-1 | openssl | 1.1.1n-0+deb11u2 |
| Medium | DSA-5523-1 | curl | 7.74.0-1.3+deb11u10 |
| Medium | DSA-5417-1 | openssl | 1.1.1n-0+deb11u5 |
| Medium | DSA-5103-1 | openssl | 1.1.1k-1+deb11u2 |
| Medium | DSA-5140-1 | openldap | 2.4.57+dfsg-3+deb11u1 |
| Medium | DEBIAN-CVE-2021-21707 | php7.4 | 7.4.28-1+deb11u1 |
| Medium | DSA-5343-1 | openssl | 1.1.1n-0+deb11u4 |
| Medium | DSA-5179-1 | php7.4 | 7.4.30-1+deb11u1 |
| Medium | DLA-3942-1 | openssl | 1.1.1n-0+deb11u6 |
| Medium | DLA-3942-2 | openssl | 1.1.1w-0+deb11u2 |
| Medium | DSA-5111-1 | zlib | 1:1.2.11.dfsg-2+deb11u1 |
| Medium | DSA-5277-1 | php7.4 | 7.4.33-1+deb11u1 |
| Medium | DEBIAN-CVE-2021-21708 | php7.4 | 7.4.28-1+deb11u1 |
| Medium | GHSA-cg3q-j54f-5p7p | github.com/ | 1.11.1 |
| Medium | DSA-5660-1 | php7.4 | 7.4.33-1+deb11u5 |
| Medium | DSA-5085-1 | expat | 2.2.10-2+deb11u2 |
| Medium | DSA-5197-1 | curl | 7.74.0-1.3+deb11u2 |
| Medium | DEBIAN-CVE-2022-31625 | php7.4 | 7.4.30-1+deb11u1 |
| Medium | DSA-5082-1 | php7.4 | 7.4.28-1+deb11u1 |
| Medium | DSA-5271-1 | libxml2 | 2.9.10+dfsg-6.7+deb11u3 |
| Medium | DSA-5216-1 | libxslt | 1.1.34-4+deb11u1 |
| Medium | DLA-3980-1 | python3.9 | 3.9.2-1+deb11u2 |
| Medium | DSA-5218-1 | zlib | 1:1.2.11.dfsg-2+deb11u2 |
| Medium | GHSA-6g8q-qfpv-57wp | cakephp/ | 4.2.12 |
| Medium | DEBIAN-CVE-2022-31630 | php7.4 | 7.4.33-1+deb11u1 |
| Medium | DLA-3920-1 | php7.4 | 7.4.33-1+deb11u6 |
| Medium | GO-2022-0433 | stdlib | 1.17.9 |
| Medium | GHSA-8xf4-w7qw-pjjw | firebase/ | 6.0.0 |
| Medium | DLA-4087-1 | python3.9 | 3.9.2-1+deb11u3 |
| Medium | GHSA-8r3f-844c-mc37 | google.golang.org/ | 1.33.0 |
| Medium | GO-2021-0243 | stdlib | 1.15.14 |
| Medium | GO-2022-0273 | stdlib | 1.16.8 |
| Medium | GHSA-p782-xgp4-8hr8 | golang.org/ | 0.0.0-20220412211240-33da011f77ad |
| Medium | GHSA-4f99-4q7p-p3gh | github.com/ | 1.8.3 |
| Medium | DSA-5286-1 | krb5 | 1.18.3-6+deb11u3 |
| Medium | GHSA-xv3h-4844-9h36 | laminas/ | 2.18.1 |
| Medium | DLA-4445-1 | python3.9 | 3.9.2-1+deb11u4 |
| Medium | GO-2022-1144 | stdlib | 1.18.9 |
| Low | DSA-5122-1 | gzip | 1.10-4+deb11u1 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.1.17latest | 3 years ago | 3.4.0-ce-non-root | 1543235 | 3,543 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.