StackRadar

CVE-2023-25193

High

Advisory

Published 4 Feb 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
259
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
6 of 6
affected packages

Red Hat Security Advisory: harfbuzz security update

Carried by container images the latest versions of 259 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
harfbuzzdeb1.7.2-1ubuntu1, 2.6.4-1ubuntu4, 2.6.4-1ubuntu4.2, 2.7.4-1ubuntu3+2 more2.6.4-1ubuntu4.3, 2.7.4-1ubuntu3.2213
harfbuzzrpm1.7.5-3.el8, 2.7.4-8.el90:1.7.5-4.el8, 0:2.7.4-10.el930
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+5 more11.0.20+8-1ubuntu1~18.04, 11.0.20+8-1ubuntu1~20.0415
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+4 more11.0.208
Javabitnami11.0.20-8, 17.0.8-711.0.203
openjdk-17deb17.0.3+7-0ubuntu0.20.04.117.0.8+7-1~20.04.21
OSV records
BIT-java-2023-25193DEBIAN-CVE-2023-25193RHSA-2024:2410RHSA-2024:2980UBUNTU-CVE-2023-25193
Also known as
BIT-java-min-2023-25193, BIT-jre-2023-25193, USN-6263-1, USN-7251-1

Charts affected

259 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
harfbuzz@6.0.0+dfsg-3
no fix listed

Open the chart page →

10,795
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3

Open the chart page →

11,405
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
11.0.20
11.0.20

Open the chart page →

9,397
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

6,016

Container images carrying it

252 by charts deploying them

A fixed version is listed for 6 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
harfbuzz@1.7.2-1ubuntu1
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
harfbuzz@2.6.4-1ubuntu4.2
openjdk-lts@11.0.16+8-0ubuntu1~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
harfbuzz@6.0.0+dfsg-3
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
harfbuzz@6.0.0+dfsg-3
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
harfbuzz@6.0.0+dfsg-3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
harfbuzz@6.0.0+dfsg-3
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
harfbuzz@6.0.0+dfsg-3
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
harfbuzz@6.0.0+dfsg-3
no fix listed
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.