CVE-2023-28320
MediumAdvisory
Published 26 May 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.027
- 85th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 173
- of 17,781 indexed, latest versions
- Container images
- 140
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 173 of 17,781 indexed charts deploy, on 140 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+17 more | 8.1.0-r0 | 140 |
- OSV records
- ALPINE-CVE-2023-28320
Charts affected
173 by stars
Container images carrying it
140 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pnnlmiscscripts/ | 05827b9efa7b | curl | 8.1.0-r0 | 10 |
| quay.io/ | c8958d9533c7 | curl | 8.1.0-r0 | 6 |
| quay.io/ | 2ad610626658 | curl | 8.1.0-r0 | 6 |
| ghcr.io/ | 947882bf2c37 | curl | 8.1.0-r0 | 5 |
| hyperledger/ | b1194f509085 | curl | 8.1.0-r0 | 4 |
| groundnuty/ | c14d7271e401 | curl | 8.1.0-r0 | 3 |
| lachlanevenson/ | e4d83478963b | curl | 8.1.0-r0 | 3 |
| pnnlmiscscripts/ | 9a2fe06a1472 | curl | 8.1.0-r0 | 3 |
| quay.io/ | 8e54bc2d261f | curl | 8.1.0-r0 | 3 |
| registry.k8s.io/ | 4ba73c697770 | curl | 8.1.0-r0 | 3 |
| cs3org/ | 02a9e78757b4 | curl | 8.1.0-r0 | 2 |
| dependencytrack/ | 24422d762e08 | curl | 8.1.0-r0 | 2 |
| devopsjourney1/ | bd1ec6838570 | curl | 8.1.0-r0 | 2 |
| filebrowser/ | 86e8449ff8ff | curl | 8.1.0-r0 | 2 |
| hashicorp/ | e38576edcdfd | curl | 8.1.0-r0 | 2 |
| k0sproject/ | f04635825d51 | curl | 8.1.0-r0 | 2 |
| krtk6160/ | cc82a694f818 | curl | 8.1.0-r0 | 2 |
| lachlanevenson/ | af5cea3f2e40 | curl | 8.1.0-r0 | 2 |
| library/ | 44a366dd7724 | curl | 8.1.0-r0 | 2 |
| metabase/ | 1fb334ce4820 | curl | 8.1.0-r0 | 2 |
| phpipam/ | f770577cb946 | curl | 8.1.0-r0 | 2 |
| phpipam/ | 3c6fd1332aeb | curl | 8.1.0-r0 | 2 |
| taigaio/ | 570c8792ce80 | curl | 8.1.0-r0 | 2 |
| ghcr.io/ | f04718704dab | curl | 8.1.0-r0 | 2 |
| quay.io/ | e98d13459cdc | curl | 8.1.0-r0 | 2 |
| quay.io/ | dc5d1ed91c26 | curl | 8.1.0-r0 | 2 |
| ahmedinfraplus/ | c50e6e81a637 | curl | 8.1.0-r0 | 1 |
| akaunting/ | e7d5c245b1a0 | curl | 8.1.0-r0 | 1 |
| alpine/ | 66b210a97bc0 | curl | 8.1.0-r0 | 1 |
| alpine/ | 00ac10bcb759 | curl | 8.1.0-r0 | 1 |
| anonaddy/ | 957a95565166 | curl | 8.1.0-r0 | 1 |
| aquasec/ | 973d0df16189 | curl | 8.1.0-r0 | 1 |
| assistiot/ | 20338b353aaf | curl | 8.1.0-r0 | 1 |
| assistiot/ | 3fe850384689 | curl | 8.1.0-r0 | 1 |
| assistiot/ | 25fc9f373524 | curl | 8.1.0-r0 | 1 |
| bicarus/ | 06cab48e9334 | curl | 8.1.0-r0 | 1 |
| blockscout/ | c365a8f2dc12 | curl | 8.1.0-r0 | 1 |
| casbin/ | 66f836ef778b | curl | 8.1.0-r0 | 1 |
| chaosnative/ | 07b82a82a702 | curl | 8.1.0-r0 | 1 |
| charmcli/ | 39523c1a6ba8 | curl | 8.1.0-r0 | 1 |
| clastix/ | 87fabaccb3a6 | curl | 8.1.0-r0 | 1 |
| clastix/ | d0376d87ac6b | curl | 8.1.0-r0 | 1 |
| crazymax/ | fb307f5b87bf | curl | 8.1.0-r0 | 1 |
| devopstales/ | 75136aa7a26e | curl | 8.1.0-r0 | 1 |
| dipugodocker/ | d431c37fe1cd | curl | 8.1.0-r0 | 1 |
| dnsforge/ | 4d9a685c8c28 | curl | 8.1.0-r0 | 1 |
| dtzar/ | a1041bb0f1d1 | curl | 8.1.0-r0 | 1 |
| eclipseaerios/ | 2f93bfa4cf0d | curl | 8.1.0-r0 | 1 |
| emqx/ | 1d36535ba9de | curl | 8.1.0-r0 | 1 |
| ethereumoptimism/ | 5577036dc36d | curl | 8.1.0-r0 | 1 |