StackRadar

CVE-2023-28320

Medium

Advisory

Published 26 May 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.027
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
173
of 17,781 indexed, latest versions
Container images
140
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 173 of 17,781 indexed charts deploy, on 140 images.

Affected packageAffected versionsFixed inImages
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+17 more8.1.0-r0140
OSV records
ALPINE-CVE-2023-28320

Charts affected

173 by stars
ChartLatestAffected imagesRadar Score
k8s-node-image-1-23pnnl-miscscripts0.2.1231 of 2See more

k8s-node-image-1-23 pnnl-miscscripts 0.2.123

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.1.0-r0

Open the chart page →

1,403
k8s-node-image-1-24pnnl-miscscripts0.2.1281 of 2See more

k8s-node-image-1-24 pnnl-miscscripts 0.2.128

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.1.0-r0

Open the chart page →

1,403
k8s-node-image9-1-21pnnl-miscscripts0.2.381 of 2See more

k8s-node-image9-1-21 pnnl-miscscripts 0.2.38

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.1.0-r0

Open the chart page →

2,612
k8s-node-image9-1-22pnnl-miscscripts0.2.311 of 2See more

k8s-node-image9-1-22 pnnl-miscscripts 0.2.31

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.1.0-r0

Open the chart page →

2,612
k8s-node-image9-1-23pnnl-miscscripts0.2.271 of 2See more

k8s-node-image9-1-23 pnnl-miscscripts 0.2.27

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.1.0-r0

Open the chart page →

2,612
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
curl@7.83.1-r2
8.1.0-r0

Open the chart page →

2,578
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
curl@7.80.0-r0
8.1.0-r0
reportportal/service-ui:5.7.20a08784eb901
curl@7.83.1-r1
8.1.0-r0

Open the chart page →

25,737
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
curl@7.80.0-r6
8.1.0-r0
quay.io/devtron/kubectl:latest2ad610626658
curl@7.83.1-r3
8.1.0-r0

Open the chart page →

68,240
devtron-operatorromholdings0.23.32 of 11See more

devtron-operator romholdings 0.23.3

2 of the 11 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
curl@7.80.0-r6
8.1.0-r0
quay.io/devtron/kubectl:latest2ad610626658
curl@7.83.1-r3
8.1.0-r0

Open the chart page →

32,902
svn-git-syncromholdings0.1.31 of 1See more

svn-git-sync romholdings 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
quay.io/devtron/svn-git-sync:v78e54bc2d261f
curl@7.83.1-r1
8.1.0-r0

Open the chart page →

1,860
scalyr-k8snode-managerscalyr-k8snode-managerVerified publisher0.1.71 of 1See more

scalyr-k8snode-manager scalyr-k8snode-manager 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
curl@7.80.0-r1
8.1.0-r0

Open the chart page →

2,150
serviceexampleserviceexample0.1.01 of 5See more

serviceexample serviceexample 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.1.0-r0

Open the chart page →

5,449
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
curl@7.83.1-r4
8.1.0-r0

Open the chart page →

2,825
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
library/nginx:1.23.2-alpine455c39afebd4
curl@7.83.1-r4
8.1.0-r0

Open the chart page →

3,462
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
curl@7.83.1-r4
8.1.0-r0

Open the chart page →

3,073
webapp1test-helm-chart-10.1.01 of 1See more

webapp1 test-helm-chart-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
curl@7.83.1-r2
8.1.0-r0

Open the chart page →

1,469
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
curl@7.83.1-r2
8.1.0-r0

Open the chart page →

3,296
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
curl@7.83.1-r3
8.1.0-r0

Open the chart page →

8,607
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.1.0-r0

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.1.0-r0

Open the chart page →

1,523
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.1.0-r0

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.1.0-r0

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-28320.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.1.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.1.0-r0

Open the chart page →

16,083

Container images carrying it

140 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
curl@7.80.0-r0
8.1.0-r0
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.1.0-r0
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.1.0-r0
1
thirtythreeforty/neolink:latestf564c4f538de
curl@8.0.1-r2
8.1.0-r0
1
vaultwarden/server:1.27.0-alpine7cd450642c54
curl@7.87.0-r0
8.1.0-r0
1
xvilo/php:8.2-composera138e57d3204
curl@7.87.0-r1
8.1.0-r0
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
curl@7.83.1-r4
8.1.0-r0
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
curl@7.83.1-r2
8.1.0-r0
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
curl@7.87.0-r1
8.1.0-r0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
curl@7.83.1-r2
8.1.0-r0
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
curl@7.80.0-r1
8.1.0-r0
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
curl@7.87.0-r1
8.1.0-r0
1
ghcr.io/k10app/businit:latest94c9a3e799c2
curl@7.86.0-r1
8.1.0-r0
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
curl@7.83.1-r1
8.1.0-r0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
curl@7.87.0-r2
8.1.0-r0
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
curl@7.83.1-r4
8.1.0-r0
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
curl@8.0.1-r2
8.1.0-r0
1
ghcr.io/reitermarkus/strongswan:v1.0.0e7a8afe6e6eb
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
curl@8.0.1-r0
8.1.0-r0
1
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
curl@7.83.1-r2
8.1.0-r0
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.1.0-r0
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.1.0-r0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
curl@7.83.1-r1
8.1.0-r0
1
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
curl@7.83.1-r4
8.1.0-r0
1
quay.io/netwarps/blockscoutbecd3e39360a
curl@7.80.0-r0
8.1.0-r0
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
curl@7.80.0-r0
8.1.0-r0
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
curl@8.0.1-r0
8.1.0-r0
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
curl@7.83.1-r3
8.1.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
curl@7.87.0-r1
8.1.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
curl@7.83.1-r3
8.1.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
curl@7.88.1-r1
8.1.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
curl@7.83.1-r2
8.1.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.