CVE-2023-0767
HighAdvisory
Published 15 Feb 2023In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.8
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 105
- of 17,781 indexed, latest versions
- Container images
- 103
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
Red Hat Security Advisory: nss security update
Carried by container images the latest versions of 105 of 17,781 indexed charts deploy, on 103 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nssdeb | 2:3.17.1-0ubuntu0.14.04.1, 2:3.28.4-0ubuntu0.14.04.3, 2:3.28.4-0ubuntu0.16.04.3, 2:3.28.4-0ubuntu0.16.04.4+16 more | 2:3.28.4-0ubuntu0.14.04.5+esm12, 2:3.28.4-0ubuntu0.16.04.14+esm4, 2:3.35-2ubuntu2.16, 2:3.49.1-1ubuntu1.9+2 more | 53 |
| nssrpm | 3.36.0-7.1.el7_6, 3.44.0-4.el7, 3.44.0-7.el7_7, 3.53.1-3.el7_9+5 more | 0:3.79.0-5.el7_9, 0:3.79.0-11.el8_7 | 49 |
| mozjs68deb | 68.6.0-1ubuntu1 | no fix listed | 1 |
- OSV records
- RHSA-2023:1252RHSA-2023:1332UBUNTU-CVE-2023-0767DSA-5353-1
- Also known as
- RHSA-2023:1369, RHSA-2023:1370, USN-5892-1, USN-5892-2
Charts affected
105 by stars
Container images carrying it
103 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | e383ba3e0966 | nss | 0:3.79.0-11.el8_7 | 1 |
| quay.io/ | c6a934439421 | nss | 2:3.28.4-0ubuntu0.16.04.14+esm4 | 1 |
| quay.io/ | 6ba82beff18e | nss | 0:3.79.0-11.el8_7 | 1 |