StackRadar

CVE-2023-29401

Medium

Advisory

Published 11 May 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
73
of 17,781 indexed, latest versions
Container images
82
deployed by those charts
Fix available
1 of 1
affected package

Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function

Carried by container images the latest versions of 73 of 17,781 indexed charts deploy, on 82 images.

Affected packageAffected versionsFixed inImages
github.com/gin-gonic/gingolangv1.4.0, v1.4.1-0.20190910091637-9aa870f108a1, v1.5.0, v1.6.3+9 more1.9.182
OSV records
GHSA-2c4m-59x9-fr2g
Also known as
GO-2023-1737

Charts affected

73 by stars
ChartLatestAffected imagesRadar Score
iomeshkubesphere-stable1.1.01 of 25See more

iomesh kubesphere-stable 1.1.0

1 of the 25 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
iomesh/operator:v1.1.060081c9b2f52
github.com/gin-gonic/gin@v1.6.3
1.9.1

Open the chart page →

48,665
IOMeshkubesphere-stable1.2.01 of 25See more

IOMesh kubesphere-stable 1.2.0

1 of the 25 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
iomesh/operator:v1.2.0ba4dd6be7e59
github.com/gin-gonic/gin@v1.6.3
1.9.1

Open the chart page →

46,341
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-auth-go:latest6597b26959d2
github.com/gin-gonic/gin@v1.9.0
1.9.1

Open the chart page →

5,905
cameramedia-streaming-meshVerified publisher0.2.51 of 3See more

camera media-streaming-mesh 0.2.5

1 of the 3 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
github.com/gin-gonic/gin@v1.8.1
1.9.1

Open the chart page →

18,608
msm-rtspmedia-streaming-meshVerified publisher0.0.21 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

1 of the 2 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
github.com/gin-gonic/gin@v1.8.1
1.9.1

Open the chart page →

18,608
rtspmedia-streaming-meshVerified publisher0.0.141 of 2See more

rtsp media-streaming-mesh 0.0.14

1 of the 2 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
github.com/gin-gonic/gin@v1.8.1
1.9.1

Open the chart page →

18,608
karmamesosphere1.3.01 of 1See more

karma mesosphere 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.503751e5eed656
github.com/gin-gonic/gin@v1.4.1-0.20190910091637-9aa870f108a1
1.9.1

Open the chart page →

2,111
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
github.com/gin-gonic/gin@v1.6.3
1.9.1

Open the chart page →

1,966
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
github.com/gin-gonic/gin@v1.5.0
1.9.1

Open the chart page →

68,284
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
github.com/gin-gonic/gin@v1.9.0
1.9.1

Open the chart page →

2,470
replacermosquitto-helm-chart0.2.01 of 3See more

replacer mosquitto-helm-chart 0.2.0

1 of the 3 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
github.com/gin-gonic/gin@v1.7.4
1.9.1

Open the chart page →

3,929
fsmopenshift0.1.8-ubi.62 of 6See more

fsm openshift 0.1.8-ubi.6

2 of the 6 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
github.com/gin-gonic/gin@v1.7.7
1.9.1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
github.com/gin-gonic/gin@v1.7.7
1.9.1

Open the chart page →

16,556
hammondpascaliskeVerified publisher2.0.01 of 2See more

hammond pascaliske 2.0.0

1 of the 2 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
github.com/gin-gonic/gin@v1.7.1
1.9.1

Open the chart page →

1,806
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
github.com/gin-gonic/gin@v1.9.0
1.9.1

Open the chart page →

1,974
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
github.com/gin-gonic/gin@v1.4.0
1.9.1

Open the chart page →

4,158
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.15.29242b4df9e65
github.com/gin-gonic/gin@v1.8.1
1.9.1

Open the chart page →

26,840
zincromholdings0.1.21 of 1See more

zinc romholdings 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
github.com/gin-gonic/gin@v1.8.1
1.9.1

Open the chart page →

1,507
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
github.com/gin-gonic/gin@v1.8.2
1.9.1

Open the chart page →

5,582
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/gin-gonic/gin@v1.8.2
1.9.1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/gin-gonic/gin@v1.8.2
1.9.1

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/gin-gonic/gin@v1.8.2
1.9.1

Open the chart page →

1,815
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
github.com/gin-gonic/gin@v1.7.2
1.9.1

Open the chart page →

4,357
twitter-apptwitter-helm0.1.122 of 8See more

twitter-app twitter-helm 0.1.12

2 of the 8 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
github.com/gin-gonic/gin@v1.8.1
1.9.1
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/gin-gonic/gin@v1.7.7
1.9.1

Open the chart page →

6,132
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-29401.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/gin-gonic/gin@v1.6.3
1.9.1

Open the chart page →

4,382

Container images carrying it

82 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
tdengine/tdengine:3.0.2.24140a4021ddb
github.com/gin-gonic/gin@v1.7.4
1.9.1
1
thecampagnards/trafficlight-api:main7dca9d973837
github.com/gin-gonic/gin@v1.7.2
1.9.1
1
voidxmh/xmh-auther:v193e42a569ca8
github.com/gin-gonic/gin@v1.7.2
1.9.1
1
voidxmh/xmh-cacher:v11b7397412320
github.com/gin-gonic/gin@v1.7.2
1.9.1
1
voidxmh/xmh-ui:v12ff3f2146547
github.com/gin-gonic/gin@v1.7.2
1.9.1
1
youssef11gaber10/deployment-auth-go:latest6597b26959d2
github.com/gin-gonic/gin@v1.9.0
1.9.1
1
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
github.com/gin-gonic/gin@v1.7.2
1.9.1
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/gin-gonic/gin@v1.6.3
1.9.1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
github.com/gin-gonic/gin@v1.8.1
1.9.1
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
github.com/gin-gonic/gin@v1.8.1
1.9.1
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
github.com/gin-gonic/gin@v1.8.1
1.9.1
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
github.com/gin-gonic/gin@v1.7.7
1.9.1
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
github.com/gin-gonic/gin@v1.7.7
1.9.1
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
github.com/gin-gonic/gin@v1.8.1
1.9.1
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
github.com/gin-gonic/gin@v1.7.7
1.9.1
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
github.com/gin-gonic/gin@v1.8.1
1.9.1
1
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
github.com/gin-gonic/gin@v1.7.0
1.9.1
1
ghcr.io/kube-logging/log-generator:v0.4.105aa441b20aa
github.com/gin-gonic/gin@v1.7.4
1.9.1
1
ghcr.io/kube-logging/log-generator:v0.6.08324bbc0ec08
github.com/gin-gonic/gin@v1.9.0
1.9.1
1
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
github.com/gin-gonic/gin@v1.7.4
1.9.1
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
github.com/gin-gonic/gin@v1.7.7
1.9.1
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/gin-gonic/gin@v1.8.2
1.9.1
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/gin-gonic/gin@v1.8.2
1.9.1
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/gin-gonic/gin@v1.8.2
1.9.1
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
github.com/gin-gonic/gin@v1.5.0
1.9.1
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/gin-gonic/gin@v1.7.3
1.9.1
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
github.com/gin-gonic/gin@v1.8.2
1.9.1
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
github.com/gin-gonic/gin@v1.8.1
1.9.1
1
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
github.com/gin-gonic/gin@v1.7.4
1.9.1
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
github.com/gin-gonic/gin@v1.9.0
1.9.1
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
github.com/gin-gonic/gin@v1.7.7
1.9.1
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
github.com/gin-gonic/gin@v1.7.7
1.9.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.