StackRadar

gitlab 4.2.3 Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Version 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDLA-2977-1xz-utils@5.2.2-1.2+b15.2.2-1.2+deb9u1
LowALPINE-CVE-2021-22924curl@7.69.1-r07.78.0-r0
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
LowGHSA-9v8j-x534-2fx3ruby-saml@1.7.21.18.0
LowGHSA-78vq-9j56-wrfrgon@6.2.06.4.0
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
LowDLA-2904-1expat@2.2.0-2+deb9u32.2.0-2+deb9u4
LowGHSA-vg3r-rm7w-2xghrexml@3.1.93.2.7
LowDLA-2378-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u2
LowGO-2021-0142stdlib@go1.13.91.13.15
LowGHSA-7359-3c6r-hfc2oauth@0.5.40.5.5
LowGO-2021-0263stdlib@go1.13.91.16.10
LowGO-2023-1571stdlib@go1.13.91.19.6
LowDLA-2773-1curl@7.52.1-5+deb9u107.52.1-5+deb9u16
LowGHSA-h8w8-99g7-qmvjconcurrent-ruby@1.1.61.3.7
LowDLA-2437-1krb5@1.15-1+deb9u11.15-1+deb9u2
LowALPINE-CVE-2021-22923curl@7.69.1-r07.78.0-r0
LowGHSA-2cw7-v8ff-p88roj@3.10.63.17.3
LowGHSA-475m-ph3x-64gpoj@3.10.63.17.3
LowGHSA-9cv6-qcjw-4grxoj@3.10.63.17.3
LowGHSA-m578-w5vf-rfcmoj@3.10.63.17.3
LowGHSA-vwm4-62gf-x745oj@3.10.63.17.3
LowGHSA-mxw3-3hh2-x2mhrack@2.0.92.2.22
LowGHSA-pp92-crg2-gfv9oauth2@1.4.42.0.22
LowGHSA-6xw4-3v39-52mmrack@2.0.92.2.20
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.24.01.83.1
LowDLA-2931-1cyrus-sasl2@2.1.27~101-g0780600+dfsg-3+deb9u12.1.27~101-g0780600+dfsg-3+deb9u2
LowGO-2022-0435stdlib@go1.13.91.17.9
LowDLA-3044-1glib2.0@2.50.3-2+deb9u22.50.3-2+deb9u3
LowGHSA-99pg-grm5-qq3vgithub.com/docker/cli@v0.0.0-20181219132003-336b2a5cac7f20.10.9
LowGHSA-9pmc-p236-855hcss_parser@1.7.03.0.0
LowGHSA-f5ww-cq3m-q3g7sanitize@4.6.66.0.2
LowGO-2022-0288golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.0.0-20211209124913-491a49abca63
LowGO-2022-0288stdlib@go1.13.91.16.12
LowGHSA-rrfc-7g8p-99q8rails-html-sanitizer@1.3.01.4.4
LowGHSA-vmwr-mc7x-5vc3rexml@3.1.93.3.6
LowGO-2021-0069stdlib@go1.14.11.14.12
LowGHSA-8cgq-6mh2-7j6vrack@2.0.92.2.12
LowGO-2023-2102stdlib@go1.13.91.20.10
LowGHSA-625h-95r8-8xpmrack@2.0.92.2.18
LowDLA-2382-1curl@7.52.1-5+deb9u107.52.1-5+deb9u12
LowDLA-3012-1libxml2@2.9.4+dfsg1-2.2+deb9u22.9.4+dfsg1-2.2+deb9u7
LowGHSA-2x63-gw47-w4mmwebsocket-driver@0.7.10.8.2
LowDLA-2837-1gmp@2:6.1.2+dfsg-12:6.1.2+dfsg-1+deb9u1
LowGHSA-w9pc-fmgc-vxvwrack@2.0.92.2.19
LowGO-2022-0236stdlib@go1.13.91.15.12
LowGO-2021-0226stdlib@go1.13.91.14.8
LowDLA-2340-2sqlite3@3.16.2-5+deb9u13.16.2-5+deb9u3
LowGHSA-9h9g-93gc-623hrails-html-sanitizer@1.3.01.4.4
LowGHSA-3v45-f3vh-wg7moj@3.10.63.17.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.