StackRadar

CVE-2023-23931

Medium

Advisory

Published 7 Feb 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
242
of 17,781 indexed, latest versions
Container images
210
deployed by those charts
Fix available
2 of 2
affected packages

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Carried by container images the latest versions of 242 of 17,781 indexed charts deploy, on 210 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.9, 2.1.4, 2.2.2, 2.3+31 more39.0.1210
python-cryptographydeb2.1.4-1ubuntu1.2, 2.1.4-1ubuntu1.3, 2.1.4-1ubuntu1.4, 2.6.1-3+3 more2.6.1-3+deb10u3, 2.8-3ubuntu0.2, 3.4.8-1ubuntu2.123
OSV records
GHSA-w7pp-m8wf-vj6rUBUNTU-CVE-2023-23931DLA-3331-1
Also known as
DLA-3331-2, PYSEC-2023-11, USN-6539-1

Charts affected

242 by stars
ChartLatestAffected imagesRadar Score
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

5,203
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

6,668
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
cryptography@3.4.8
39.0.1

Open the chart page →

2,201
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
cryptography@38.0.4
39.0.1

Open the chart page →

15,591
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3

Open the chart page →

10,466
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
cryptography@38.0.4
39.0.1

Open the chart page →

30,219
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
cryptography@3.4.8
39.0.1

Open the chart page →

7,295
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
cryptography@2.6.1
39.0.1

Open the chart page →

4,744
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
cryptography@3.4.8
39.0.1

Open the chart page →

1,318
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
cryptography@3.4
39.0.1

Open the chart page →

21,997
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
cryptography@2.8
39.0.1

Open the chart page →

8,694
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,803
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
cryptography@37.0.2
39.0.1

Open the chart page →

7,574
gar-exportersoftonic0.1.11 of 1See more

gar-exporter softonic 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
softonic/gar-exporter:0.2.1a64d6c0e0ae5
cryptography@3.2.1
39.0.1

Open the chart page →

2,296
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
cryptography@2.8
python-cryptography@2.8-3ubuntu0.1
39.0.1
2.8-3ubuntu0.2

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
cryptography@2.6.1
39.0.1

Open the chart page →

2,060
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
cryptography@3.1.1
39.0.1

Open the chart page →

3,044
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
cryptography@2.5
39.0.1

Open the chart page →

18,756
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

7,244
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

1,955
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

17,461
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
cryptography@38.0.1
39.0.1

Open the chart page →

8,607
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

3,176
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
cryptography@3.4.8
39.0.1

Open the chart page →

13,459
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
39.0.1

Open the chart page →

11,119
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
39.0.1

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
39.0.1

Open the chart page →

2,643
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1

Open the chart page →

1,636

Container images carrying it

210 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-zookeeper:6.1.078c190f4472c
cryptography@3.3.1
39.0.1
1
daskdev/dask:1.1.04ecd7bc35500
cryptography@2.3.1
39.0.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
cryptography@2.3.1
39.0.1
1
datadog/agent:7.22.08f20e56b5311
cryptography@2.8
39.0.1
1
datadog/agent:6aad9994de6a7
cryptography@3.3.2
39.0.1
1
deconzcommunity/deconz:2.29.2062de2362641
cryptography@38.0.4
39.0.1
1
deconzcommunity/deconz:2.12.066541bbb78952
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
cryptography@3.4.6
39.0.1
1
deepflowce/mysql:8.0.313d7ae561cf60
cryptography@3.4.7
39.0.1
1
devopstales/trivy-operator:2.575136aa7a26e
cryptography@39.0.0
39.0.1
1
dnationcloud/kubernetes-linter:0.2.1dee6376560f5
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3
1
douz/helpdesk:latest4384103d0219
cryptography@2.8
39.0.1
1
dpage/pgadmin4:4.5a5a656e1d5fd
cryptography@2.6.1
39.0.1
1
dpage/pgadmin4:4.22b1f00b8163cf
cryptography@2.9.2
39.0.1
1
drgrove/mtls-server:v0.14.2361721759a2b
cryptography@2.4.2
39.0.1
1
dysnix/pritunl:v1.29-r819951e3e7a32
cryptography@2.8
39.0.1
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
cryptography@2.8
39.0.1
1
errbotio/errbot:6.1.900ee4e0953ab
cryptography@37.0.2
39.0.1
1
esphome/esphome:1.18.03f51ec10e823
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
cryptography@2.7
39.0.1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
cryptography@39.0.0
39.0.1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
cryptography@2.8
39.0.1
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
cryptography@37.0.4
39.0.1
1
fossology/fossology:4.2.18bd1f22ba7bb
cryptography@38.0.3
39.0.1
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
cryptography@37.0.2
39.0.1
1
galaxy/cloudman-server:lateste5c265fe9fcd
cryptography@38.0.1
39.0.1
1
galaxy/galaxy-init:v18.010267bad550e6
cryptography@2.2.2
39.0.1
1
gethue/hue:4.11.011b649636e68
cryptography@36.0.1
39.0.1
1
gethue/hue:4.10.05702b2c37ff9
cryptography@3.3.2
python-cryptography@2.1.4-1ubuntu1.4
39.0.1
no fix listed
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
cryptography@2.6.1
39.0.1
1
gluufederation/opendj:4.3.0_011a1128b28b95
cryptography@3.3.2
39.0.1
1
goofball222/pritunl:1.30.3070.5943c0743701d4
cryptography@3.4.7
39.0.1
1
goofball222/pritunl:1.32.3602.807bf26032dfce
cryptography@38.0.4
39.0.1
1
helga09/my_sql_shoes:v1.1.1a03657d97897
cryptography@37.0.2
39.0.1
1
hhyo/archery:v1.9.11aa41843419e
cryptography@38.0.1
39.0.1
1
hjacobs/kube-resource-report:21.2.145f93491c434
cryptography@3.4.1
39.0.1
1
hjacobs/kube-resource-report:22.11.0c173cd02f5af
cryptography@38.0.4
39.0.1
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
cryptography@3.1.1
39.0.1
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
cryptography@37.0.2
39.0.1
1
improwised/erpnext-worker:v13.4.197280b55cbd4
cryptography@3.4.7
39.0.1
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
39.0.1
1
jertel/elastalert2:2.2.34dcc0ef93efc
cryptography@35.0.0
39.0.1
1
jmferrer/azure-devops-agent:latest030f68ec6998
cryptography@2.8
39.0.1
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
39.0.1
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
cryptography@3.2.1
39.0.1
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
cryptography@3.4.7
39.0.1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
cryptography@3.1.1
39.0.1
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
cryptography@3.1.1
39.0.1
1
kennethreitz/httpbin:latest599fe5e50731
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.2
39.0.1
no fix listed
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
cryptography@2.7
39.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.