StackRadar

CVE-2023-23931

Medium

Advisory

Published 7 Feb 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
242
of 17,781 indexed, latest versions
Container images
210
deployed by those charts
Fix available
2 of 2
affected packages

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Carried by container images the latest versions of 242 of 17,781 indexed charts deploy, on 210 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.9, 2.1.4, 2.2.2, 2.3+31 more39.0.1210
python-cryptographydeb2.1.4-1ubuntu1.2, 2.1.4-1ubuntu1.3, 2.1.4-1ubuntu1.4, 2.6.1-3+3 more2.6.1-3+deb10u3, 2.8-3ubuntu0.2, 3.4.8-1ubuntu2.123
OSV records
GHSA-w7pp-m8wf-vj6rUBUNTU-CVE-2023-23931DLA-3331-1
Also known as
DLA-3331-2, PYSEC-2023-11, USN-6539-1

Charts affected

242 by stars
ChartLatestAffected imagesRadar Score
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

5,203
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

6,668
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
cryptography@3.4.8
39.0.1

Open the chart page →

2,201
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
cryptography@38.0.4
39.0.1

Open the chart page →

15,591
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3

Open the chart page →

10,466
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
cryptography@38.0.4
39.0.1

Open the chart page →

30,219
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
cryptography@3.4.8
39.0.1

Open the chart page →

7,295
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
cryptography@2.6.1
39.0.1

Open the chart page →

4,744
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
cryptography@3.4.8
39.0.1

Open the chart page →

1,318
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
cryptography@3.4
39.0.1

Open the chart page →

21,997
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
cryptography@2.8
39.0.1

Open the chart page →

8,694
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,803
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
cryptography@37.0.2
39.0.1

Open the chart page →

7,574
gar-exportersoftonic0.1.11 of 1See more

gar-exporter softonic 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
softonic/gar-exporter:0.2.1a64d6c0e0ae5
cryptography@3.2.1
39.0.1

Open the chart page →

2,296
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
cryptography@2.8
python-cryptography@2.8-3ubuntu0.1
39.0.1
2.8-3ubuntu0.2

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
cryptography@2.6.1
39.0.1

Open the chart page →

2,060
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
cryptography@3.1.1
39.0.1

Open the chart page →

3,044
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
cryptography@2.5
39.0.1

Open the chart page →

18,756
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

7,244
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

1,955
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

17,461
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
cryptography@38.0.1
39.0.1

Open the chart page →

8,607
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

3,176
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
cryptography@3.4.8
39.0.1

Open the chart page →

13,459
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
39.0.1

Open the chart page →

11,119
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
39.0.1

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
39.0.1

Open the chart page →

2,643
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1

Open the chart page →

1,636

Container images carrying it

210 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
cryptography@2.6.1
39.0.1
1
kobotoolbox/kobocat:2.022.24ab15679454415
cryptography@36.0.2
39.0.1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
cryptography@36.0.2
39.0.1
1
library/mysql:8.0.303c1aab708f6e
cryptography@3.4.7
39.0.1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
cryptography@3.4.8
39.0.1
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
cryptography@2.5
39.0.1
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
cryptography@2.8
39.0.1
1
linuxserver/deluge:18.04.10ac871624394
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.4
39.0.1
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.4
39.0.1
no fix listed
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
cryptography@3.4.7
39.0.1
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.4
39.0.1
no fix listed
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
cryptography@2.8
39.0.1
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
cryptography@36.0.2
39.0.1
1
lncm/specter-desktop:v0.10.4bca14d04397d
cryptography@3.2
39.0.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
cryptography@38.0.4
39.0.1
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
cryptography@2.6.1
39.0.1
1
louislam/uptime-kuma:13d632903e6af
cryptography@2.6.1
39.0.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
cryptography@38.0.4
39.0.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
cryptography@38.0.4
39.0.1
1
louislam/uptime-kuma:2.4.091e963bfda56
cryptography@38.0.4
39.0.1
1
louislam/uptime-kuma:1.23.1396510915e6be
cryptography@2.6.1
39.0.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
cryptography@38.0.4
39.0.1
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3
1
louislam/uptime-kuma:1.18.5a84767d7934f
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
cryptography@2.6.1
39.0.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
cryptography@36.0.1
39.0.1
1
lsstsqre/prepuller:latest19c2dfc4e4ff
cryptography@3.4.7
39.0.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
cryptography@3.4.7
39.0.1
1
lsstsqre/wfdispatcher:lateste9feb99f524d
cryptography@3.4.7
39.0.1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
cryptography@36.0.1
39.0.1
1
milesmcc/shynet:v0.12.0e821e31140f7
cryptography@36.0.1
39.0.1
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
cryptography@3.0
39.0.1
1
mozilla/syncserver:latest016162bf39d8
cryptography@2.6.1
39.0.1
1
mozilla/syncstorage-rs:0.15.893752877dced
cryptography@3.4.8
39.0.1
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
cryptography@2.3.1
39.0.1
1
mysql/mysql-cluster:8.0.20e4ea36622cdd
cryptography@2.8
39.0.1
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
cryptography@2.3
39.0.1
1
neilpeterson/get-tweet:v28b645ac1a23e
cryptography@2.2.2
39.0.1
1
neilpeterson/osba-storage-demo:latest29d229ab446e
cryptography@2.1.4
39.0.1
1
neilpeterson/process-tweet:latest39ce9f92e899
cryptography@2.2.2
39.0.1
1
netbirdio/dashboard:v2.90.101b59e1c905c9
cryptography@3.3.2
39.0.1
1
netbirdio/dashboard:v2.90.2332cc31f5f35
cryptography@3.3.2
39.0.1
1
netboxcommunity/netbox:v3.2.83d652dca5351
cryptography@37.0.4
39.0.1
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
cryptography@3.1.1
39.0.1
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
cryptography@36.0.2
39.0.1
1
nlmacamp/check_mk:latest5dbb8589f824
cryptography@2.3.1
39.0.1
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.3
39.0.1
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
cryptography@2.3.1
39.0.1
1
opendatacube/restcube:latest91870111837c
cryptography@2.7
39.0.1
1
opendatacube/wms:latest1b90cdf68831
cryptography@2.7
39.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.