StackRadar

CVE-2023-25193

High

Advisory

Published 4 Feb 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
259
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
6 of 6
affected packages

Red Hat Security Advisory: harfbuzz security update

Carried by container images the latest versions of 259 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
harfbuzzdeb1.7.2-1ubuntu1, 2.6.4-1ubuntu4, 2.6.4-1ubuntu4.2, 2.7.4-1ubuntu3+2 more2.6.4-1ubuntu4.3, 2.7.4-1ubuntu3.2213
harfbuzzrpm1.7.5-3.el8, 2.7.4-8.el90:1.7.5-4.el8, 0:2.7.4-10.el930
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+5 more11.0.20+8-1ubuntu1~18.04, 11.0.20+8-1ubuntu1~20.0415
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+4 more11.0.208
Javabitnami11.0.20-8, 17.0.8-711.0.203
openjdk-17deb17.0.3+7-0ubuntu0.20.04.117.0.8+7-1~20.04.21
OSV records
BIT-java-2023-25193DEBIAN-CVE-2023-25193RHSA-2024:2410RHSA-2024:2980UBUNTU-CVE-2023-25193
Also known as
BIT-java-min-2023-25193, BIT-jre-2023-25193, USN-6263-1, USN-7251-1

Charts affected

259 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

9,347
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
harfbuzz@6.0.0+dfsg-3
no fix listed

Open the chart page →

10,795
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3

Open the chart page →

11,405
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
11.0.20
11.0.20

Open the chart page →

9,397
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2

Open the chart page →

14,100
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-25193.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8

Open the chart page →

6,016

Container images carrying it

252 by charts deploying them

A fixed version is listed for 6 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
harfbuzz@6.0.0+dfsg-3
no fix listed
5
ciscolabs/rtsp-client:latesta7b60ec88285
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
3
ciscolabs/rtsp-server:latestb59fc10bb821
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
3
library/node:ltsbe23f54a88d3
harfbuzz@6.0.0+dfsg-3
no fix listed
3
signoz/zookeeper:3.7.1fcc4a3288154
java@11.0.20-8-5
Java@11.0.20-8
11.0.20
11.0.20
3
quay.io/devtron/ai-agent:0.0.16545dac92173
harfbuzz@6.0.0+dfsg-3
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
harfbuzz@6.0.0+dfsg-3
no fix listed
3
apache/druid:37.0.00116fb802786
harfbuzz@6.0.0+dfsg-3
no fix listed
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
11.0.20
11.0.20
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
harfbuzz@6.0.0+dfsg-3
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
harfbuzz@2.6.4-1ubuntu4
openjdk-17@17.0.3+7-0ubuntu0.20.04.1
2.6.4-1ubuntu4.3
17.0.8+7-1~20.04.2
2
library/python:3.7eedf63967cdb
harfbuzz@6.0.0+dfsg-3
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
harfbuzz@6.0.0+dfsg-3
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
harfbuzz@6.0.0+dfsg-3
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
harfbuzz@6.0.0+dfsg-3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
harfbuzz@6.0.0+dfsg-3
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
harfbuzz@6.0.0+dfsg-3
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
harfbuzz@6.0.0+dfsg-3
no fix listed
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
harfbuzz@6.0.0+dfsg-3
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
harfbuzz@6.0.0+dfsg-3
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
harfbuzz@6.0.0+dfsg-3
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
harfbuzz@6.0.0+dfsg-3
no fix listed
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
2
5200710/hadoop:3.2.3-java8092d3088a5fb
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
harfbuzz@2.6.4-1ubuntu4
2.6.4-1ubuntu4.3
1
andrianrf/backoffice-be:latest6036614803d4
harfbuzz@2.7.4-8.el9
0:2.7.4-10.el9
1
andrianrf/iso-server:latest7da47f525c7d
harfbuzz@2.7.4-8.el9
0:2.7.4-10.el9
1
anguda/ant-media:2.5c435285fc241
harfbuzz@2.6.4-1ubuntu4.2
openjdk-lts@11.0.18+10-0ubuntu1~20.04.1
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
anujdatar/cups:25.07.01685df04a643b
harfbuzz@6.0.0+dfsg-3
no fix listed
1
apache/druid:29.0.10cef139b6bf1
harfbuzz@6.0.0+dfsg-3
no fix listed
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.13+8-0ubuntu1~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
apachepulsar/pulsar:2.9.0d056c89b7131
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.11+9-0ubuntu2~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
apachepulsar/pulsar:2.8.2d538416d5afe
harfbuzz@2.6.4-1ubuntu4
openjdk-lts@11.0.13+8-0ubuntu1~20.04
2.6.4-1ubuntu4.3
11.0.20+8-1ubuntu1~20.04
1
apache/tika:2.9.0.092d055a84e9e
harfbuzz@2.7.4-1ubuntu3.1
2.7.4-1ubuntu3.2
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
archivebox/archivebox:0.7.41a5a37331091
harfbuzz@6.0.0+dfsg-3
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
harfbuzz@6.0.0+dfsg-3
no fix listed
1
assistiot/identity-manager_kc:latest0df4b4fa899a
harfbuzz@1.7.5-3.el8
0:1.7.5-4.el8
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
harfbuzz@6.0.0+dfsg-3
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
harfbuzz@2.6.4-1ubuntu4.2
2.6.4-1ubuntu4.3
1
avinash263/pyredis263:latestaa2b8727f1a6
harfbuzz@6.0.0+dfsg-3
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
harfbuzz@6.0.0+dfsg-3
no fix listed
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
java@17.0.7-7-2
11.0.20
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
java@11.0.18-10-2
11.0.20
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
java@11.0.15-150
11.0.20
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
java@17.0.6-10-4
11.0.20
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.