StackRadar

CVE-2023-25193

High

Advisory

Published 4 Feb 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
259
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
6 of 6
affected packages

Red Hat Security Advisory: harfbuzz security update

Carried by container images the latest versions of 259 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
harfbuzzdeb1.7.2-1ubuntu1, 2.6.4-1ubuntu4, 2.6.4-1ubuntu4.2, 2.7.4-1ubuntu3+2 more2.6.4-1ubuntu4.3, 2.7.4-1ubuntu3.2213
harfbuzzrpm1.7.5-3.el8, 2.7.4-8.el90:1.7.5-4.el8, 0:2.7.4-10.el930
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+5 more11.0.20+8-1ubuntu1~18.04, 11.0.20+8-1ubuntu1~20.0415
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+4 more11.0.208
Javabitnami11.0.20-8, 17.0.8-711.0.203
openjdk-17deb17.0.3+7-0ubuntu0.20.04.117.0.8+7-1~20.04.21
OSV records
BIT-java-2023-25193DEBIAN-CVE-2023-25193RHSA-2024:2410RHSA-2024:2980UBUNTU-CVE-2023-25193
Also known as
BIT-java-min-2023-25193, BIT-jre-2023-25193, USN-6263-1, USN-7251-1

Charts affected

259 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
harfbuzz@6.0.0+dfsg-3
no fix listed

Open the chart page →

10,795
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3

Open the chart page →

11,405
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
11.0.20
11.0.20

Open the chart page →

9,397
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

6,016

Container images carrying it

252 by charts deploying them

A fixed version is listed for 6 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
louislam/uptime-kuma:2.5.33e24e96c89ef
harfbuzz@6.0.0+dfsg-3
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
harfbuzz@6.0.0+dfsg-3
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
harfbuzz@6.0.0+dfsg-3
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
harfbuzz@6.0.0+dfsg-3
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
harfbuzz@6.0.0+dfsg-3
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
harfbuzz@6.0.0+dfsg-3
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
mockserver/mockserver:mockserver-7.6.080b3b1a26f35
harfbuzz@6.0.0+dfsg-3
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
harfbuzz@6.0.0+dfsg-3
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
harfbuzz@6.0.0+dfsg-3
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
harfbuzz@6.0.0+dfsg-3
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
harfbuzz@6.0.0+dfsg-3
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
harfbuzz@6.0.0+dfsg-3
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
harfbuzz@1.7.2-1ubuntu1
openjdk-lts@11.0.3+7-1ubuntu2~18.04.1
no fix listed
11.0.20+8-1ubuntu1~18.04
1
oneuptime/probe:release6b2d98713711
harfbuzz@6.0.0+dfsg-3
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
harfbuzz@6.0.0+dfsg-3
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
harfbuzz@6.0.0+dfsg-3
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
harfbuzz@6.0.0+dfsg-3
no fix listed
1
opea/speecht5:1.0249afad3d268
harfbuzz@6.0.0+dfsg-3
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
harfbuzz@6.0.0+dfsg-3
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
openproject/hocuspocus:release-338001b288dc1359dfb5
harfbuzz@6.0.0+dfsg-3
no fix listed
1
owncloud/server:10.15.051d9b74fc2a8
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
penpotapp/backend:2.2.147853d9bb9dd
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
penpotapp/exporter:2.2.15c835ffd87ab
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
harfbuzz@6.0.0+dfsg-3
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
harfbuzz@2.7.4-1ubuntu3
2.7.4-1ubuntu3.2
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
java@17.0.8-7-5
Java@17.0.8-7
11.0.20
11.0.20
1
project2team4/react:latest3ff031a08887
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.14.1+1-0ubuntu1~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
rm3l/dev-feed-api:latest9a7f732245a3
harfbuzz@2.7.4-8.el9
0:2.7.4-10.el9
1
ryshe/terraria:latestb1c89f7f359a
harfbuzz@6.0.0+dfsg-3
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
harfbuzz@6.0.0+dfsg-3
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
harfbuzz@6.0.0+dfsg-3
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
harfbuzz@1.7.2-1ubuntu1
no fix listed
1
signalen/backend:2.50.14760256000738
harfbuzz@6.0.0+dfsg-3
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
harfbuzz@1.7.2-1ubuntu1
openjdk-lts@11.0.8+10-0ubuntu1~18.04.1
no fix listed
11.0.20+8-1ubuntu1~18.04
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
harfbuzz@6.0.0+dfsg-3
no fix listed
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
harfbuzz@6.0.0+dfsg-3
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
harfbuzz@6.0.0+dfsg-3
no fix listed
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
harfbuzz@6.0.0+dfsg-3
no fix listed
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
harfbuzz@6.0.0+dfsg-3
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
speckle/speckle-preview-service:2.26.3092384dba45d
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
harfbuzz@6.0.0+dfsg-3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.