StackRadar

CVE-2023-29491

High

Advisory

Published 14 Apr 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
810
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: ncurses security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 810 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+2 more5.9+20140118-1ubuntu1+esm3, 6.0+20160213-1ubuntu1+esm3, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1+1 more443
ncursesapk6.3_p20211120-r0, 6.3_p20211120-r1, 6.3_p20220423-r0, 6.3_p20220521-r0+1 more6.3_p20211120-r2, 6.3_p20220521-r1, 6.3_p20221119-r1206
ncursesrpm6.1-7.20180224.el8, 6.1-9.20180224.el8, 6.1-9.20180224.el8_6.1, 6.1-150000.5.12.1+1 more0:6.1-9.20180224.el8_8.1, 0:6.2-10.20210508.el9, 6.1-150000.5.15.1161
OSV records
ALPINE-CVE-2023-29491RHSA-2023:5249RHSA-2023:6698UBUNTU-CVE-2023-29491SUSE-SU-2023:2111-1
Also known as
RHSA-2023:7361, RHSA-2024:0416, USN-6099-1

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
ncurses@6.3_p20221119-r0
6.3_p20221119-r1

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
yandex/clickhouse-server:21.3.204eccfffb01d7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1

Open the chart page →

9,250

Container images carrying it

810 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
andrianrf/backoffice-be:latest6036614803d4
ncurses@6.2-8.20210508.el9
0:6.2-10.20210508.el9
1
andrianrf/iso-server:latest7da47f525c7d
ncurses@6.2-8.20210508.el9
0:6.2-10.20210508.el9
1
anguda/ant-media:2.5c435285fc241
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
anonaddy/anonaddy:0.12.3957a95565166
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
apache/camel-k:1.10.43bb13d14f64a
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
apache/iotdb:0.13.3-nodeafa47bf1692a
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
apachepulsar/pulsar:2.9.0d056c89b7131
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
apachepulsar/pulsar:2.8.2d538416d5afe
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
apache/skywalking-oap-server:9.2.0133d35d2c263
ncurses@6.3-2
6.3-2ubuntu0.1
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
apache/skywalking-ui:9.2.0295f1dc87d98
ncurses@6.3-2
6.3-2ubuntu0.1
1
apache/skywalking-ui:8.9.180530f0308a5
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
apache/tika:2.9.0.092d055a84e9e
ncurses@6.3-2
6.3-2ubuntu0.1
1
apecloud/pyroscope:0.37.2dbca95a15bc1
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
aquasec/kube-bench:v0.6.9c329d73fea58
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
asonix/pictrs:0.4.0-beta.19480d36cd97e5
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
assistiot/identity-manager_kc:latest0df4b4fa899a
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
assistiot/location_processing:lateste9bae124095f
ncurses@6.3-2
6.3-2ubuntu0.1
1
assistiot/open_api_kong:1.0.03fe850384689
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
assistiot/tacticle_dashboard:db-latest02bc92348156
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
atlassian/confluence-server:7.10.03b9222ab32ef
ncurses@6.3-2
6.3-2ubuntu0.1
1
balihb/block-pvc-scanner:0.2.45b95e1cf1158
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
bicarus/mx-notifier:1.1.8bed688d16762
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
bicarus/wg-access-server:v0.8.206cab48e9334
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
blockscout/blockscout:5.1.5c365a8f2dc12
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
bsgrigorov/helm-operator:latest45ab095f09c8
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
chaosnative/cle-frontend:2.7.007b82a82a702
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
ncurses@5.9+20140118-1ubuntu1
5.9+20140118-1ubuntu1+esm3
1
chetangautamm/repo:sipp.v3e7f7049e1544
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
cheyang/distributed-tf:1.6.046cc34755493
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
citizenstig/httpbin:latestb81c818ccb86
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
ncurses@6.3-2
6.3-2ubuntu0.1
1
cloudve/janis-terminal:latestaf56e77ca587
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
cloudve/ttyd:latestd79c1c5881c0
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.