StackRadar

CVE-2023-23915

Medium

Advisory

Published 15 Feb 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
183
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 183 images.

Affected packageAffected versionsFixed inImages
curlapk7.77.0-r1, 7.78.0-r0, 7.79.1-r0, 7.79.1-r1+15 more7.79.1-r5, 7.80.0-r6, 7.83.1-r6, 7.87.0-r2151
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+1 more7.81.0-1ubuntu1.832
OSV records
ALPINE-CVE-2023-23915UBUNTU-CVE-2023-23915
Also known as
USN-5891-1

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-23915.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
7.80.0-r6

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-23915.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
7.80.0-r6

Open the chart page →

1,523
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-23915.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
7.80.0-r6

Open the chart page →

7,552
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-23915.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
curl@7.79.1-r0
7.79.1-r5

Open the chart page →

3,359
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-23915.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
7.80.0-r6
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
7.80.0-r6

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-23915.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
curl@7.79.1-r0
7.79.1-r5

Open the chart page →

2,534

Container images carrying it

183 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
phntom/postgresql-backup-s3:1.0.2249b6488f618b
curl@7.86.0-r1
7.87.0-r2
1
photoprism/photoprism:220629-jammy2954334adbda
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.8
1
pnnlmiscscripts/k8s-node-image:1.18.20-nginx-323bfca2cfaaaf
curl@7.79.1-r1
7.79.1-r5
1
pnnlmiscscripts/k8s-node-image:1.17.17-nginx-3685debe11edc4
curl@7.79.1-r1
7.79.1-r5
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
curl@7.83.1-r1
7.83.1-r6
1
pnnlmiscscripts/k8s-node-image:1.19.16-nginx-20c5c2b19e53a2
curl@7.79.1-r1
7.79.1-r5
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
curl@7.83.1-r4
7.83.1-r6
1
prefapp/nginx-proxified:latestf4d026fd9a26
curl@7.83.1-r3
7.83.1-r6
1
qumine/minecraft-server:v0.1.15c0b650d51132
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.8
1
reportportal/migrations:5.7.0da5d8e1395fe
curl@7.80.0-r0
7.80.0-r6
1
reportportal/service-ui:5.7.20a08784eb901
curl@7.83.1-r1
7.83.1-r6
1
soulou2019/angular-nginx:latesta3970f97c215
curl@7.80.0-r0
7.80.0-r6
1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
curl@7.80.0-r1
7.80.0-r6
1
swaggerapi/swagger-ui:v4.12.00d7088d47928
curl@7.80.0-r1
7.80.0-r6
1
swaggerapi/swagger-ui:v4.15.511b20aebb92c
curl@7.83.1-r3
7.83.1-r6
1
swaggerapi/swagger-ui:v4.15.27ff9a86f35ff
curl@7.83.1-r3
7.83.1-r6
1
t3nde/matomo:4.3.1-fpm-alpine329ce194393a
curl@7.77.0-r1
7.79.1-r5
1
taemon1337/image-api:0.0.1247bc1dc4f07
curl@7.80.0-r0
7.80.0-r6
1
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
curl@7.80.0-r0
7.80.0-r6
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
7.80.0-r6
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
7.80.0-r6
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.8
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
curl@7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.8
1
tomsquest/docker-radicale:3.1.1.04759cc353a1d
curl@7.79.1-r0
7.79.1-r5
1
trafex/php-nginx:2.4.07282edfca2bf
curl@7.79.1-r0
7.79.1-r5
1
trafex/php-nginx:2.2.0ee0b7c6cce07
curl@7.79.1-r0
7.79.1-r5
1
trinodb/trino:405ee80ab5eeab2
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.8
1
vaultwarden/server:1.27.0-alpine7cd450642c54
curl@7.87.0-r0
7.87.0-r2
1
vectorim/riot-web:v1.7.3384bb5af00b5d
curl@7.77.0-r1
7.79.1-r5
1
vitorbari/jwks-merge:v0.1.0fd3ccb820ada
curl@7.79.1-r0
7.79.1-r5
1
weetmuts/wmbusmeters:release-1.4.1-amd64a79967400c61
curl@7.78.0-r0
7.79.1-r5
1
wener/frpc:v0.37.0cc9fd4da44c0
curl@7.79.1-r0
7.79.1-r5
1
wener/frps:v0.37.05c92cc9e8597
curl@7.79.1-r0
7.79.1-r5
1
wistefan/mvf:lateste0887302b2d8
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.8
1
xvilo/php:8.2-composera138e57d3204
curl@7.87.0-r1
7.87.0-r2
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.8
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.8
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.8
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
curl@7.83.1-r4
7.83.1-r6
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
curl@7.83.1-r2
7.83.1-r6
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
7.80.0-r6
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
curl@7.87.0-r1
7.87.0-r2
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
curl@7.78.0-r0
7.79.1-r5
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
curl@7.83.1-r2
7.83.1-r6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.