StackRadar

gitlab 4.2.3 Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Version 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-ggxm-pgc9-g7fprdoc@6.1.26.1.2.1
MediumGHSA-w6pv-c757-6rgrapollo_upload_server@2.0.0.beta.32.1.0
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
MediumGHSA-5866-49gr-22v4rexml@3.1.93.3.3
MediumDLA-2369-1libxml2@2.9.4+dfsg1-2.2+deb9u22.9.4+dfsg1-2.2+deb9u3
MediumGHSA-69p3-xp37-f692kubeclient@4.6.04.9.3
MediumGHSA-hggm-jpg3-v476cryptography@3.03.2
MediumGHSA-gjh7-p2fx-99vxrack@2.0.92.2.14
MediumGHSA-7wqh-767x-r66vrack@2.0.92.2.13
MediumGHSA-3ww4-gg4f-jr7fcryptography@3.042.0.0
MediumGHSA-gwc9-m7rh-j2wwgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.0.0-20211202192323-5770296d904e
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
MediumGHSA-3x8r-x6xp-q4vmloofah@2.5.02.19.1
MediumGHSA-9xrj-h377-fr87activestorage@6.0.3.17.2.3.1
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
MediumDLA-2492-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u2
MediumDLA-2493-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u3
MediumGO-2021-0243stdlib@go1.13.91.15.14
MediumGO-2022-0273stdlib@go1.13.91.16.8
MediumGHSA-p782-xgp4-8hr8golang.org/x/sys@v0.0.0-20200113162924-86b910548bc10.0.0-20220412211240-33da011f77ad
MediumGHSA-73f9-jhhh-hr5mactivestorage@6.0.3.17.2.3.1
MediumALPINE-CVE-2020-14145openssh@8.3_p1-r08.3_p1-r1
MediumGHSA-4f99-4q7p-p3ghgithub.com/sirupsen/logrus@v1.4.21.8.3
MediumGHSA-2j26-frm8-cmj9activesupport@6.0.3.17.2.3.1
MediumGHSA-r46p-8f7g-vvvgactivestorage@6.0.3.17.2.3.1
MediumDLA-2734-1curl@7.52.1-5+deb9u107.52.1-5+deb9u15
MediumGHSA-mm33-5vfq-3mm3actionpack@6.0.3.16.0.4.8
MediumGHSA-hqxw-f8mx-cpmwgithub.com/docker/distribution@v2.7.0+incompatible2.8.2-beta.1
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
MediumGHSA-p543-xpfm-54cprack@2.0.92.2.19
MediumGHSA-wpv5-97wm-hp9crack@2.0.92.2.19
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.35.0
MediumGHSA-2rqw-v265-jf8cactionpack@6.0.3.16.0.4.1
MediumDLA-2972-1libxml2@2.9.4+dfsg1-2.2+deb9u22.9.4+dfsg1-2.2+deb9u6
MediumGHSA-cfjv-5498-mph5actionview@6.0.3.16.0.3.3
MediumGHSA-ch3h-j2vf-95pvactionview@6.0.3.16.0.4.8
MediumGHSA-v95c-p5hm-xq8fgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.0.3
MediumGO-2022-1144stdlib@go1.13.91.18.9
MediumGHSA-6v2p-p543-phr9golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d0.27.0
MediumGHSA-w7pp-m8wf-vj6rcryptography@3.039.0.1
MediumGHSA-5pq7-52mg-hr42httparty@0.16.40.21.0
MediumPYSEC-2024-225cryptography@3.042.0.4
MediumDLA-2664-1curl@7.52.1-5+deb9u107.52.1-5+deb9u14
MediumGHSA-xrx6-fmxq-rjj2rsa@4.64.7
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.4.80.6.3
MediumGHSA-5xp3-jfq3-5q8xpip@20.1.121.1
LowGHSA-9493-h29p-rfm2github.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.2.8
LowALPINE-CVE-2022-27774curl@7.69.1-r07.79.1-r1
LowGHSA-7g2v-jj9q-g3rgrack@2.0.92.2.11
LowDLA-2976-1gzip@1.6-5+b11.6-5+deb9u1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.