StackRadar

CVE-2023-23931

Medium

Advisory

Published 7 Feb 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
242
of 17,781 indexed, latest versions
Container images
210
deployed by those charts
Fix available
2 of 2
affected packages

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Carried by container images the latest versions of 242 of 17,781 indexed charts deploy, on 210 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.9, 2.1.4, 2.2.2, 2.3+31 more39.0.1210
python-cryptographydeb2.1.4-1ubuntu1.2, 2.1.4-1ubuntu1.3, 2.1.4-1ubuntu1.4, 2.6.1-3+3 more2.6.1-3+deb10u3, 2.8-3ubuntu0.2, 3.4.8-1ubuntu2.123
OSV records
GHSA-w7pp-m8wf-vj6rUBUNTU-CVE-2023-23931DLA-3331-1
Also known as
DLA-3331-2, PYSEC-2023-11, USN-6539-1

Charts affected

242 by stars
ChartLatestAffected imagesRadar Score
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

5,203
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

6,668
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
cryptography@3.4.8
39.0.1

Open the chart page →

2,201
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
cryptography@38.0.4
39.0.1

Open the chart page →

15,591
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3

Open the chart page →

10,466
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
cryptography@38.0.4
39.0.1

Open the chart page →

30,219
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
cryptography@3.4.8
39.0.1

Open the chart page →

7,295
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
cryptography@2.6.1
39.0.1

Open the chart page →

4,744
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
cryptography@3.4.8
39.0.1

Open the chart page →

1,318
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
cryptography@3.4
39.0.1

Open the chart page →

21,997
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
cryptography@2.8
39.0.1

Open the chart page →

8,694
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,803
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1

Open the chart page →

25,769
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
cryptography@37.0.2
39.0.1

Open the chart page →

7,574
gar-exportersoftonic0.1.11 of 1See more

gar-exporter softonic 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
softonic/gar-exporter:0.2.1a64d6c0e0ae5
cryptography@3.2.1
39.0.1

Open the chart page →

2,296
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
cryptography@2.8
python-cryptography@2.8-3ubuntu0.1
39.0.1
2.8-3ubuntu0.2

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
cryptography@2.6.1
39.0.1

Open the chart page →

2,060
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
cryptography@3.1.1
39.0.1

Open the chart page →

3,044
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
cryptography@2.5
39.0.1

Open the chart page →

18,756
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

7,244
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1

Open the chart page →

1,955
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

17,461
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
cryptography@38.0.1
39.0.1

Open the chart page →

8,607
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1

Open the chart page →

3,176
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
cryptography@3.4.8
39.0.1

Open the chart page →

13,459
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
39.0.1

Open the chart page →

11,119
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
39.0.1

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
39.0.1

Open the chart page →

2,643
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-23931.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1

Open the chart page →

1,636

Container images carrying it

210 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
39.0.1
22
oomk8s/readiness-check:2.0.2875814cc853d
cryptography@2.6.1
39.0.1
11
argoproj/argocd:v1.8.1830e86cacefd
cryptography@2.6.1
python-cryptography@2.6.1-3+deb10u2
39.0.1
2.6.1-3+deb10u3
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
cryptography@35.0.0
39.0.1
3
dpage/pgadmin4:6.12781369df9994
cryptography@3.3.2
39.0.1
3
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
39.0.1
3
amancevice/superset:0.35.212a0a9e66550
cryptography@2.7
39.0.1
2
hjacobs/kube-ops-view:20.4.058221b57d4d2
cryptography@2.9.2
39.0.1
2
larribas/mlflow:1.9.105ccb0b46bfb
cryptography@2.9.2
39.0.1
2
lncm/specter-desktop:v1.10.536eaa06f99f4
cryptography@3.4.7
39.0.1
2
louislam/uptime-kuma:2.5.4917318f9d7be
cryptography@38.0.4
39.0.1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
cryptography@38.0.4
39.0.1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
cryptography@38.0.4
39.0.1
2
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
39.0.1
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
39.0.1
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
cryptography@2.3.1
39.0.1
2
weblate/weblate:4.2.2-169c160d37a3c
cryptography@3.1
39.0.1
2
ghcr.io/games-on-whales/xorg:1.0.0305b3327ebba
cryptography@3.3.2
39.0.1
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
cryptography@36.0.1
39.0.1
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
39.0.1
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.3
39.0.1
no fix listed
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
cryptography@3.3.2
39.0.1
1
acockburn/appdaemon:4.0.83a93281d7e94
cryptography@3.4.7
39.0.1
1
alerta/alerta-web:8.5.04786b9eaa606
cryptography@3.4.6
39.0.1
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
cryptography@37.0.2
python-cryptography@2.1.4-1ubuntu1.4
39.0.1
no fix listed
1
amancevice/superset:0.28.1c8c04bfe3d66
cryptography@1.9
39.0.1
1
amd64/mysql:5.7e20a653e0f51
cryptography@3.2.1
39.0.1
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
cryptography@2.9
39.0.1
1
anchore/anchore-engine:v0.10.0bde9eedf639d
cryptography@3.3.2
39.0.1
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
cryptography@2.9.2
39.0.1
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
cryptography@3.3.2
39.0.1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
cryptography@3.4.7
39.0.1
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
cryptography@3.3.2
39.0.1
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
cryptography@3.3.2
39.0.1
1
bnjbvr/kresus:0.22.137e216b182c8
cryptography@38.0.4
39.0.1
1
camptocamp/ekorre:0.1.035c91d5fda04
cryptography@2.8
39.0.1
1
camptocamp/pghoard:10bff736b15623
cryptography@2.3.1
39.0.1
1
camptocamp/snow-webhook:latest2924b43dbf40
cryptography@2.6.1
39.0.1
1
cdignam/kodiak:v0.54.05a6a55b39cee
cryptography@3.4.8
39.0.1
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
cryptography@2.6.1
python-cryptography@2.6.1-3
39.0.1
2.6.1-3+deb10u3
1
chorss/docker-pgadmin4:4.115c549cacb8ab
cryptography@2.7
39.0.1
1
cloudve/janis-terminal:latestaf56e77ca587
cryptography@2.1.4
python-cryptography@2.1.4-1ubuntu1.3
39.0.1
no fix listed
1
cloudve/ttyd:latestd79c1c5881c0
cryptography@2.9.2
39.0.1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
cryptography@3.3.1
39.0.1
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
cryptography@3.3.1
39.0.1
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
cryptography@3.4.8
39.0.1
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
cryptography@3.3.1
39.0.1
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
cryptography@3.3.1
39.0.1
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
cryptography@3.3.1
39.0.1
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
cryptography@3.3.1
39.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.