StackRadar

CVE-2023-25690

Critical

Advisory

Published 7 Mar 2023In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.845
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
4 of 4
affected packages

Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.122.4.41-4ubuntu3.147
apache2apk2.4.53-r0, 2.4.54-r0, 2.4.54-r1, 2.4.55-r02.4.56-r05
apachebitnami2.4.54-1572.4.561
httpdrpm2.4.37-43.module+el8.5.0+13806+b30d9eec.10:2.4.37-51.module+el8.7.0+18499+2e106f0b.51
OSV records
ALPINE-CVE-2023-25690BIT-apache-2023-25690RHSA-2023:1673UBUNTU-CVE-2023-25690
Also known as
USN-5942-1

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

18,509
phpipamstackhelmVerified publisher0.1.22 of 3See more

phpipam stackhelm 0.1.2

2 of the 3 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.5.2f770577cb946
apache2@2.4.55-r0
2.4.56-r0
phpipam/phpipam-www:v1.5.23c6fd1332aeb
apache2@2.4.55-r0
2.4.56-r0

Open the chart page →

1,874
phpipamvquieVerified publisher1.0.32 of 3See more

phpipam vquie 1.0.3

2 of the 3 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.5.2f770577cb946
apache2@2.4.55-r0
2.4.56-r0
phpipam/phpipam-www:v1.5.23c6fd1332aeb
apache2@2.4.55-r0
2.4.56-r0

Open the chart page →

7,025
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
apache2@2.4.54-r0
2.4.56-r0

Open the chart page →

7,534
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.56

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.56

Open the chart page →

7,541
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14

Open the chart page →

20,933
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

14,659
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
apache2@2.4.53-r0
2.4.56-r0

Open the chart page →

8,392
rtorrent-rutorrentgeek-cookbookVerified publisher1.1.21 of 1See more

rtorrent-rutorrent geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
apache2@2.4.54-r1
2.4.56-r0

Open the chart page →

4,232
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

10,248
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

22,658
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

9,167
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14

Open the chart page →

30,687
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-25690.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-51.module+el8.7.0+18499+2e106f0b.5

Open the chart page →

6,671

Container images carrying it

14 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
phpipam/phpipam-cron:v1.5.2f770577cb946
apache2@2.4.55-r0
2.4.56-r0
2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
apache2@2.4.55-r0
2.4.56-r0
2
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.56
2
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
apache2@2.4.54-r1
2.4.56-r0
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
apache2@2.4.54-r0
2.4.56-r0
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
openemr/openemr:6.1.089eaa6d9a4e3
apache2@2.4.53-r0
2.4.56-r0
1
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14
1
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-51.module+el8.7.0+18499+2e106f0b.5
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.