StackRadar

CVE-2019-11038

Medium

Advisory

Published 11 Jun 2019In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.043
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
28
of 17,781 indexed, latest versions
Container images
26
deployed by those charts
Fix available
2 of 2
affected packages

libgd2 - security update

Carried by container images the latest versions of 28 of 17,781 indexed charts deploy, on 26 images.

Affected packageAffected versionsFixed inImages
libgd2deb2.1.0-3ubuntu0.8, 2.1.0-5+deb8u11, 2.1.1-4ubuntu0.16.04.8, 2.1.1-4ubuntu0.16.04.10+1 more2.1.0-3ubuntu0.11+esm1, 2.1.0-5+deb8u13, 2.1.1-4ubuntu0.16.04.12, 2.2.5-4ubuntu0.416
gdapk2.2.5-r1, 2.2.5-r22.2.5-r310
OSV records
ALPINE-CVE-2019-11038UBUNTU-CVE-2019-11038DLA-1817-1
Also known as
USN-4316-1, USN-4316-2

Charts affected

28 by stars
ChartLatestAffected imagesRadar Score
swaggeruicetic0.3.61 of 1See more

swaggerui cetic 0.3.6

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:v3.24.3d434cac93813
gd@2.2.5-r2
2.2.5-r3

Open the chart page →

976
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
openzipkin/zipkin-ui:2.21.0672cbc94256b
gd@2.2.5-r2
2.2.5-r3

Open the chart page →

3,229
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
spoonest/clickhouse-tabix-web-client:stablefd2b754a5d37
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

6,761
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,425
osba-text-analytics-demoazure-sample0.1.01 of 1See more

osba-text-analytics-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,089
twitter-sentimentazure-sample0.1.01 of 3See more

twitter-sentiment azure-sample 0.1.0

1 of the 3 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
neilpeterson/get-tweet:v28b645ac1a23e
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

11,833
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
libgd2@2.2.5-4ubuntu0.2
2.2.5-4ubuntu0.4

Open the chart page →

29,901
puppet-forgecloudnativeapp0.1.81 of 2See more

puppet-forge cloudnativeapp 0.1.8

1 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
hickey/puppet_forge:1.10.0c1148a09ef20
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

4,086
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libgd2@2.1.1-4ubuntu0.16.04.8
2.1.1-4ubuntu0.16.04.12

Open the chart page →

77,758
webpagetest-servercloudnativeapp0.2.11 of 1See more

webpagetest-server cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
timothyclarke/wptserver:2018-03-0840a80ced8031
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,716
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
libgd2@2.1.0-3ubuntu0.8
2.1.0-3ubuntu0.11+esm1

Open the chart page →

70,895
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
igrantio/bb-consent-admin-dashboard:2023.11.6852574120a1e
gd@2.2.5-r1
2.2.5-r3

Open the chart page →

3,181
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
gd@2.2.5-r1
2.2.5-r3

Open the chart page →

3,871
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
library/nginx:1.17.4-alpine0649f548ea26
gd@2.2.5-r2
2.2.5-r3

Open the chart page →

4,678
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,186
comcastgeek-cookbookVerified publisher6.4.21 of 1See more

comcast geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
billimek/comcastusage-for-influxdb:latest801bba1228ac
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,245
landing-pagelsst-sqre0.3.01 of 1See more

landing-page lsst-sqre 0.3.0

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
lsstsqre/lsp-landing-page:latest4653f18b5418
gd@2.2.5-r2
2.2.5-r3

Open the chart page →

1,024
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libgd2@2.1.1-4ubuntu0.16.04.10
2.1.1-4ubuntu0.16.04.12

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libgd2@2.1.1-4ubuntu0.16.04.10
2.1.1-4ubuntu0.16.04.12

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libgd2@2.1.1-4ubuntu0.16.04.10
2.1.1-4ubuntu0.16.04.12

Open the chart page →

29,124
k8s-node-image-1-13pnnl-miscscripts0.1.252 of 2See more

k8s-node-image-1-13 pnnl-miscscripts 0.1.25

2 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20181125-1500-nginx-74eafeb809124
gd@2.2.5-r2
2.2.5-r3
pnnlmiscscripts/k8s-node-image:1.13.11-nginx-12648032cb498
gd@2.2.5-r2
2.2.5-r3

Open the chart page →

1,582
oauth2-proxypresto-loadbalancer4.3.181 of 2See more

oauth2-proxy presto-loadbalancer 4.3.18

1 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
library/nginx:1.15.9-alpine55390addbb1a
gd@2.2.5-r1
2.2.5-r3

Open the chart page →

3,958
static-siteredhat-cop0.0.241 of 2See more

static-site redhat-cop 0.0.24

1 of the 2 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
library/nginx:1.17.9-alpineabe5ce652eb7
gd@2.2.5-r2
2.2.5-r3

Open the chart page →

1,726
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
spoonest/clickhouse-tabix-web-client:stablefd2b754a5d37
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

10,967
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-11038.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13

Open the chart page →

3,116

Container images carrying it

26 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libgd2@2.1.1-4ubuntu0.16.04.10
2.1.1-4ubuntu0.16.04.12
3
spoonest/clickhouse-tabix-web-client:stablefd2b754a5d37
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
2
billimek/comcastusage-for-influxdb:latest801bba1228ac
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
daskdev/dask-notebook:1.1.0052630f5ca04
libgd2@2.2.5-4ubuntu0.2
2.2.5-4ubuntu0.4
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
galaxy/galaxy-stable:v18.018e577a626dfd
libgd2@2.1.0-3ubuntu0.8
2.1.0-3ubuntu0.11+esm1
1
hickey/puppet_forge:1.10.0c1148a09ef20
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
igrantio/bb-consent-admin-dashboard:2023.11.6852574120a1e
gd@2.2.5-r1
2.2.5-r3
1
library/nginx:1.17.4-alpine0649f548ea26
gd@2.2.5-r2
2.2.5-r3
1
library/nginx:1.15.9-alpine55390addbb1a
gd@2.2.5-r1
2.2.5-r3
1
library/nginx:1.17.9-alpineabe5ce652eb7
gd@2.2.5-r2
2.2.5-r3
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
gd@2.2.5-r1
2.2.5-r3
1
lsstsqre/lsp-landing-page:latest4653f18b5418
gd@2.2.5-r2
2.2.5-r3
1
neilpeterson/get-tweet:v28b645ac1a23e
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
neilpeterson/osba-storage-demo:latest29d229ab446e
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
openzipkin/zipkin-ui:2.21.0672cbc94256b
gd@2.2.5-r2
2.2.5-r3
1
pnnlmiscscripts/anaconda:20181125-1500-nginx-74eafeb809124
gd@2.2.5-r2
2.2.5-r3
1
pnnlmiscscripts/k8s-node-image:1.13.11-nginx-12648032cb498
gd@2.2.5-r2
2.2.5-r3
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1
swaggerapi/swagger-ui:v3.24.3d434cac93813
gd@2.2.5-r2
2.2.5-r3
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libgd2@2.1.1-4ubuntu0.16.04.8
2.1.1-4ubuntu0.16.04.12
1
timothyclarke/wptserver:2018-03-0840a80ced8031
libgd2@2.1.0-5+deb8u11
2.1.0-5+deb8u13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.