StackRadar

CVE-2023-28858

Low

Advisory

Published 26 Mar 2023In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 2
affected packages

redis-py Race Condition vulnerability

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
redispypi4.2.0, 4.2.2, 4.3.4, 4.4.0+2 more4.3.6, 4.4.3, 4.5.316
python-redisdeb4.3.4-3no fix listed3
OSV records
DEBIAN-CVE-2023-28858GHSA-24wv-mv5m-xv4hUBUNTU-CVE-2023-28858
Also known as
PYSEC-2023-45

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
redis@4.3.4
4.3.6

Open the chart page →

9,145
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6

Open the chart page →

12,170
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
redis@4.2.2
4.3.6
kobotoolbox/kpi:2.022.24dbcacc01bccd4
redis@4.2.2
4.3.6

Open the chart page →

18,517
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
redis@4.3.4
4.3.6

Open the chart page →

3,924
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
redis@4.2.2
4.3.6

Open the chart page →

8,967
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
redis@4.2.0
4.3.6

Open the chart page →

2,850
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
redis@4.3.4
4.3.6

Open the chart page →

4,085
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6

Open the chart page →

12,170
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
redis@4.4.2
4.4.3

Open the chart page →

16,417
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
redis@4.5.1
4.5.3

Open the chart page →

2,470
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.02 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

2 of the 40 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6

Open the chart page →

71,208
python-apppython-app-chart0.1.01 of 2See more

python-app python-app-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
mnaggar3396/python-app:latest371d8ed84b15
redis@4.3.4
4.3.6

Open the chart page →

3,382
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
thecloudspark/app-vote:1.0c7da7417a86a
redis@4.2.2
4.3.6

Open the chart page →

3,031
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_vote:v13a856afb02a3
redis@4.4.0
4.4.3

Open the chart page →

8,262
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_vote:v13a856afb02a3
redis@4.4.0
4.4.3

Open the chart page →

8,262
webapp-chartwebappchart1.0.01 of 1See more

webapp-chart webappchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-28858.

Container imageDigestPackageFixed in
amagdi888/my-repo:hello-appd8a10fc8faf6
redis@4.3.4
4.3.6

Open the chart page →

1,201

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kodekloud/examplevotingapp_vote:v13a856afb02a3
redis@4.4.0
4.4.3
2
vdiogov/glpi-conteiner:latest6945f84f0058
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6
2
amagdi888/my-repo:hello-appd8a10fc8faf6
redis@4.3.4
4.3.6
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
redis@4.3.4
4.3.6
1
gethue/hue:4.11.011b649636e68
redis@4.4.2
4.4.3
1
goofball222/pritunl:1.32.3602.807bf26032dfce
redis@4.5.1
4.5.3
1
kobotoolbox/kobocat:2.022.24ab15679454415
redis@4.2.2
4.3.6
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
redis@4.2.2
4.3.6
1
librenms/librenms:22.4.14f1f3d667cc7
redis@4.2.2
4.3.6
1
mnaggar3396/python-app:latest371d8ed84b15
redis@4.3.4
4.3.6
1
netboxcommunity/netbox:v3.2.83d652dca5351
redis@4.3.4
4.3.6
1
openzaak/open-notificaties:1.3.02e65313b9b10
redis@4.2.0
4.3.6
1
thecloudspark/app-vote:1.0c7da7417a86a
redis@4.2.2
4.3.6
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
python-redis@4.3.4-3
redis@4.3.4
no fix listed
4.3.6
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
redis@4.3.4
4.3.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.