StackRadar

CVE-2017-14176

High

Advisory

Published 29 Nov 2017In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.060
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 2
affected packages

Bazaar allows remote attackers to execute arbitrary commands via a bzr+ssh URL with initial dash character in hostname

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
bzrpypi2.7.0, 2.7.0dev1no fix listed16
bzrdeb2.6.0+bzr6595-6, 2.7.0+bzr6619-72.6.0+bzr6595-6+deb8u1, 2.7.0+bzr6619-7+deb9u18
OSV records
GHSA-jjxg-hpm7-g95fDSA-4052-1
Also known as
PYSEC-2017-149

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
rocketmqgin1.1.01 of 2See more

rocketmq gin 1.1.0

1 of the 2 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1

Open the chart page →

9,154
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
bzr@2.7.0dev1
no fix listed

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
bzr@2.7.0dev1
no fix listed

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
bzr@2.7.0dev1
no fix listed

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
bzr@2.7.0dev1
no fix listed

Open the chart page →

3,425
osba-text-analytics-demoazure-sample0.1.01 of 1See more

osba-text-analytics-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
bzr@2.7.0dev1
no fix listed

Open the chart page →

3,089
twitter-sentimentazure-sample0.1.01 of 3See more

twitter-sentiment azure-sample 0.1.0

1 of the 3 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
neilpeterson/get-tweet:v28b645ac1a23e
bzr@2.7.0dev1
no fix listed

Open the chart page →

11,833
imap-mailbox-exportercamptocamp32.0.01 of 1See more

imap-mailbox-exporter camptocamp3 2.0.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
camptocamp/imap-mailbox-exporter:latest9dec019e4c62
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1

Open the chart page →

2,234
ldap-search-exportercamptocamp31.0.01 of 1See more

ldap-search-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
camptocamp/ldap-search-exporter:latest5e55370dd292
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1

Open the chart page →

2,234
puppet-forgecloudnativeapp0.1.81 of 2See more

puppet-forge cloudnativeapp 0.1.8

1 of the 2 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
hickey/puppet_forge:1.10.0c1148a09ef20
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1

Open the chart page →

4,086
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1

Open the chart page →

6,497
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
bzr@2.7.0dev1
no fix listed

Open the chart page →

3,186
comcastgeek-cookbookVerified publisher6.4.21 of 1See more

comcast geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
billimek/comcastusage-for-influxdb:latest801bba1228ac
bzr@2.7.0dev1
no fix listed

Open the chart page →

3,245
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1

Open the chart page →

10,682
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
bzr@2.7.0
no fix listed

Open the chart page →

4,225
oauth2-proxyjenkins-x0.2.31 of 1See more

oauth2-proxy jenkins-x 0.2.3

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
a5huynh/oauth2_proxy:2.20c7307d31ca8
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1

Open the chart page →

2,392
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
bzr@2.7.0dev1
no fix listed

Open the chart page →

3,116
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1

Open the chart page →

8,262
workerappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1

Open the chart page →

3,329
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1

Open the chart page →

8,262
workerappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1

Open the chart page →

3,329
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2017-14176.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
bzr@2.7.0
no fix listed

Open the chart page →

4,984

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kodekloud/examplevotingapp_worker:v1741e3aaaa812
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1
4
a5huynh/oauth2_proxy:2.20c7307d31ca8
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1
1
billimek/comcastusage-for-influxdb:latest801bba1228ac
bzr@2.7.0dev1
no fix listed
1
camptocamp/imap-mailbox-exporter:latest9dec019e4c62
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1
1
camptocamp/ldap-search-exporter:latest5e55370dd292
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
bzr@2.7.0dev1
no fix listed
1
gomods/athens:v0.8.1d714c7ff0231
bzr@2.7.0
no fix listed
1
gomods/athens:v0.11.0efb811df7844
bzr@2.7.0
no fix listed
1
hickey/puppet_forge:1.10.0c1148a09ef20
bzr@2.7.0dev1
bzr@2.6.0+bzr6595-6
no fix listed
2.6.0+bzr6595-6+deb8u1
1
jenkinsci/jenkins:2.67a1f33f004659
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1
1
neilpeterson/get-tweet:v28b645ac1a23e
bzr@2.7.0dev1
no fix listed
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
bzr@2.7.0dev1
no fix listed
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
bzr@2.7.0dev1
no fix listed
1
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
bzr@2.7.0dev1
no fix listed
1
neilpeterson/osba-storage-demo:latest29d229ab446e
bzr@2.7.0dev1
no fix listed
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
bzr@2.7.0dev1
no fix listed
1
raykrueger/riemann:0.2.14c8baf3de57bb
bzr@2.7.0+bzr6619-7
2.7.0+bzr6619-7+deb9u1
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
bzr@2.7.0dev1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.