StackRadar

CVE-2023-25193

High

Advisory

Published 4 Feb 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
259
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
6 of 6
affected packages

Red Hat Security Advisory: harfbuzz security update

Carried by container images the latest versions of 259 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
harfbuzzdeb1.7.2-1ubuntu1, 2.6.4-1ubuntu4, 2.6.4-1ubuntu4.2, 2.7.4-1ubuntu3+2 more2.6.4-1ubuntu4.3, 2.7.4-1ubuntu3.2213
harfbuzzrpm1.7.5-3.el8, 2.7.4-8.el90:1.7.5-4.el8, 0:2.7.4-10.el930
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+5 more11.0.20+8-1ubuntu1~18.04, 11.0.20+8-1ubuntu1~20.0415
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+4 more11.0.208
Javabitnami11.0.20-8, 17.0.8-711.0.203
openjdk-17deb17.0.3+7-0ubuntu0.20.04.117.0.8+7-1~20.04.21
OSV records
BIT-java-2023-25193DEBIAN-CVE-2023-25193RHSA-2024:2410RHSA-2024:2980UBUNTU-CVE-2023-25193
Also known as
BIT-java-min-2023-25193, BIT-jre-2023-25193, USN-6263-1, USN-7251-1

Charts affected

259 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
harfbuzz@6.0.0+dfsg-3
no fix listed

Open the chart page →

10,795
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3

Open the chart page →

11,405
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
11.0.20
11.0.20

Open the chart page →

9,397
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

6,016

Container images carrying it

252 by charts deploying them

A fixed version is listed for 6 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
harfbuzz@6.0.0+dfsg-3
no fix listed
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
harfbuzz@6.0.0+dfsg-3
no fix listed
1
stashapp/stash:latest24dbd7607174
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
substratusai/verba:v0.4.0-baseURL261695be635eb
harfbuzz@6.0.0+dfsg-3
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
harfbuzz@6.0.0+dfsg-3
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
harfbuzz@2.6.4-1ubuntu4.2
openjdk-lts@11.0.19+7~us1-0ubuntu1~20.04.1
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
harfbuzz@6.0.0+dfsg-3
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
harfbuzz@6.0.0+dfsg-3
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
harfbuzz@6.0.0+dfsg-3
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
harfbuzz@6.0.0+dfsg-3
no fix listed
1
theradius/loggia:0.463ba348546ec
harfbuzz@6.0.0+dfsg-3
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
harfbuzz@6.0.0+dfsg-3
no fix listed
1
thongngo3301/stakefish:latesta341af5976e3
harfbuzz@6.0.0+dfsg-3
no fix listed
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
harfbuzz@6.0.0+dfsg-3
no fix listed
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
harfbuzz@6.0.0+dfsg-3
no fix listed
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
vlebediantsev/notes-admin-front:latest007c6670ff48
harfbuzz@6.0.0+dfsg-3
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
harfbuzz@6.0.0+dfsg-3
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
harfbuzz@6.0.0+dfsg-3
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
wavefronthq/proxy:9.2d1064d28f6eb
openjdk-lts@11.0.8+10-0ubuntu1~18.04.1
11.0.20+8-1ubuntu1~18.04
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
harfbuzz@6.0.0+dfsg-3
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
harfbuzz@6.0.0+dfsg-3
no fix listed
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/caninehq/canine:latesta058034ca006
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.