StackRadar

gitlab 4.2.3 Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Version 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumDLA-2960-1apache2@2.4.25-3+deb9u92.4.25-3+deb9u13
MediumDLA-2706-1apache2@2.4.25-3+deb9u92.4.25-3+deb9u10
MediumGHSA-fp4w-jxhp-m23pbundler@1.16.62.2.10
MediumALPINE-CVE-2022-23852expat@2.2.9-r12.2.10-r1
MediumGHSA-mqm2-cgpr-p4m6kramdown@2.2.12.3.0
MediumDLA-3017-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u9
MediumALPINE-CVE-2020-8285curl@7.69.1-r07.69.1-r3
MediumGHSA-r4mg-4433-c7g3activestorage@6.0.3.17.1.5.2
MediumDLA-2574-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u8
MediumALPINE-CVE-2018-1000121curl@7.57.0-r07.59.0-r0
MediumALPINE-CVE-2018-1000005curl@7.57.0-r07.58.0-r0
MediumDLA-2968-1zlib@1:1.2.8.dfsg-51:1.2.8.dfsg-5+deb9u1
MediumDLA-2563-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u3
MediumDLA-2565-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u4
MediumDLA-2766-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u4
MediumDLA-2774-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u6
MediumALPINE-CVE-2022-22823expat@2.2.9-r12.2.10-r0
MediumALPINE-CVE-2022-22824expat@2.2.9-r12.2.10-r0
MediumGHSA-83g2-8m93-v3w7golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.0.0-20210520170846-37e1c6afe023
MediumGHSA-c3xm-pvg7-gh7rgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.0.0-rc95
MediumALPINE-CVE-2021-45960expat@2.2.9-r12.2.10-r0
MediumGHSA-jphg-qwrw-7w9gjson@2.1.02.3.0
MediumGHSA-w749-p3v6-hccqactivestorage@6.0.3.16.0.4.7
MediumGHSA-v222-6mr4-qj29asciidoctor-include-ext@0.3.10.4.0
MediumGHSA-52p9-v744-mwjjkramdown@2.2.12.3.1
MediumALPINE-CVE-2019-14697musl@1.1.18-r31.1.18-r4
MediumGHSA-cg3q-j54f-5p7pgithub.com/prometheus/client_golang@v1.0.01.11.1
MediumGHSA-g6wq-qcwm-j5g2websocket-extensions@0.1.40.1.5
MediumGHSA-v4f8-2847-rwm7nokogiri@1.10.91.11.4
MediumALPINE-CVE-2022-28391busybox@1.31.1-r161.31.1-r22
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.31.0
MediumDLA-2935-1expat@2.2.0-2+deb9u32.2.0-2+deb9u5
MediumGHSA-5c5f-7vfq-3732jmespath@1.4.01.6.1
MediumALPINE-CVE-2018-16890curl@7.57.0-r07.61.1-r2
MediumGHSA-3hhc-qp5v-9p2jactiverecord@6.0.3.16.0.5.1
MediumGHSA-v5h6-c2hv-hv3rstringio@0.0.23.0.1.1
MediumGHSA-jrfj-98qg-qjgvsidekiq@5.2.95.2.10
MediumGHSA-c3h9-896r-86jmgithub.com/gogo/protobuf@v1.1.11.3.2
MediumALPINE-CVE-2021-39537ncurses@6.2_p20200523-r06.2_p20200523-r1
MediumGHSA-5f9h-9pjv-v6j7rack@2.0.92.1.3
MediumGHSA-8cr8-4vfw-mr7hrexml@3.1.93.2.5
MediumGHSA-7wjx-3g7j-8584actionpack@6.0.3.16.0.3.7
MediumDLA-2559-1busybox@1:1.22.0-19+b31:1.22.0-19+deb9u1
MediumALPINE-CVE-2021-36159apk-tools@2.10.5-r12.10.7-r0
MediumALPINE-CVE-2022-25314expat@2.2.9-r12.2.10-r2
MediumALPINE-CVE-2020-8286curl@7.69.1-r07.69.1-r3
MediumGHSA-vvpx-j8f3-3w6hgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.7.0
MediumGHSA-33c5-9fx5-fvjmk8s.io/apimachinery@v0.0.0-20191004074956-c5d2f014d6890.16.13
MediumALPINE-CVE-2021-22946curl@7.69.1-r07.79.0-r0
MediumALPINE-CVE-2022-22826expat@2.2.9-r12.2.10-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.