StackRadar

gitlab 4.2.3 Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Version 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-qphc-hf5q-v8fcactionpack@6.0.3.16.0.4.2
MediumGHSA-5cm2-9h8c-rvfxtzinfo@1.2.71.2.10
MediumGHSA-jxhc-q857-3j6gaddressable@2.7.02.8.0
MediumGHSA-w73w-5m7g-f7qcgithub.com/dgrijalva/jwt-go@v3.2.0+incompatibleno fix listed
MediumGHSA-3xh2-74w9-5vxmgithub.com/gorilla/websocket@v1.4.01.4.1
MediumALPINE-CVE-2022-25313expat@2.2.9-r12.2.10-r2
MediumGHSA-wh98-p28r-vrc9actionpack@6.0.3.16.0.4.6
MediumALPINE-CVE-2021-41617openssh@8.3_p1-r08.3_p1-r3
MediumGHSA-hxqx-xwvh-44m2rack@2.0.92.0.9.1
MediumALPINE-CVE-2021-42383busybox@1.31.1-r161.31.1-r21
MediumGHSA-wxc4-f4m6-wwqvgopkg.in/yaml.v2@v2.2.42.2.8
MediumGHSA-fj7f-vq84-fh43bundler@1.16.62.2.33
MediumGHSA-xrjj-mj9h-534mgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.4.0
MediumALPINE-CVE-2021-22876curl@7.69.1-r07.76.0-r0
MediumGHSA-5rcv-m4m3-hfh7golang.org/x/text@v0.3.20.3.3
MediumGHSA-3h57-hmj3-gj3prack@2.0.92.0.9.3
MediumGHSA-h86h-8ppg-mxmhgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.0.0-20210428140749-89ef3d95e781
MediumDLA-2848-1libssh2@1.7.0-1+deb9u11.7.0-1+deb9u2
MediumALPINE-CVE-2021-22925curl@7.69.1-r07.78.0-r0
MediumGHSA-x76w-6vjr-8xgjactionpack@6.0.3.16.1.7.9
MediumGHSA-p4x4-rw2p-8j8msanitize@4.6.65.2.1
MediumGHSA-286v-pcf5-25rcnokogiri@1.10.91.11.4
MediumGHSA-6q6q-88xp-6f2rgopkg.in/yaml.v2@v2.2.22.2.4
MediumGHSA-486f-hjj9-9vhhloofah@2.5.02.19.1
MediumGHSA-wrvw-hg22-4m67google-protobuf@3.8.03.19.2
MediumGHSA-65f5-mfpf-vfhjrack@2.0.92.0.9.2
MediumGHSA-vfg9-r3fq-jvx4actionpack@6.0.3.16.1.7.9
MediumDLA-2786-1nghttp2@1.18.1-1+deb9u11.18.1-1+deb9u2
MediumGHSA-jcr6-mmjj-pchwgithub.com/gorilla/handlers@v0.0.0-20150720190736-60c7bfde3e331.3.0
MediumDLA-2340-1sqlite3@3.16.2-5+deb9u13.16.2-5+deb9u2
MediumGHSA-69ch-w2m2-3vjpgolang.org/x/text@v0.3.20.3.8
MediumGHSA-wwhv-wxv9-rpgwactiontext@6.0.3.16.1.7.9
MediumGHSA-qcm3-vfq5-wfr2RedCloth@4.3.24.3.3
MediumGO-2022-0433stdlib@go1.13.91.17.9
MediumGHSA-92rq-c8cf-prrqruby-saml@1.7.21.12.4
MediumDLA-2500-1curl@7.52.1-5+deb9u107.52.1-5+deb9u13
MediumALPINE-CVE-2021-22947curl@7.69.1-r07.79.0-r0
MediumGHSA-h47h-mwp9-c6q6actionmailer@6.0.3.16.1.7.9
MediumGHSA-5x79-w82f-gw8wrails-html-sanitizer@1.3.01.4.4
MediumGHSA-2rr5-8q37-2w7hnokogiri@1.10.91.12.5
MediumGHSA-2rxp-v6pw-ch6mrexml@3.1.93.3.9
MediumGHSA-c6qr-h5vq-59jcactionpack@6.0.3.16.0.3.2
MediumALPINE-CVE-2020-8177curl@7.69.1-r07.69.1-r1
MediumGHSA-ppp9-7jff-5vj2golang.org/x/text@v0.3.20.3.7
MediumDLA-2715-1systemd@232-25+deb9u12232-25+deb9u13
MediumGHSA-r55c-59qm-vjw6rexml@3.1.93.3.3
MediumGHSA-579w-22j4-4749activerecord@6.0.3.16.1.7.1
MediumGHSA-9v9h-cgj8-h64pcryptography@3.042.0.2
MediumDLA-2653-1libxml2@2.9.4+dfsg1-2.2+deb9u22.9.4+dfsg1-2.2+deb9u4
MediumGHSA-g857-hhfv-j68wzlib@1.0.03.0.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.