StackRadar

CVE-2023-29491

High

Advisory

Published 14 Apr 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
810
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: ncurses security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 810 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+2 more5.9+20140118-1ubuntu1+esm3, 6.0+20160213-1ubuntu1+esm3, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1+1 more443
ncursesapk6.3_p20211120-r0, 6.3_p20211120-r1, 6.3_p20220423-r0, 6.3_p20220521-r0+1 more6.3_p20211120-r2, 6.3_p20220521-r1, 6.3_p20221119-r1206
ncursesrpm6.1-7.20180224.el8, 6.1-9.20180224.el8, 6.1-9.20180224.el8_6.1, 6.1-150000.5.12.1+1 more0:6.1-9.20180224.el8_8.1, 0:6.2-10.20210508.el9, 6.1-150000.5.15.1161
OSV records
ALPINE-CVE-2023-29491RHSA-2023:5249RHSA-2023:6698UBUNTU-CVE-2023-29491SUSE-SU-2023:2111-1
Also known as
RHSA-2023:7361, RHSA-2024:0416, USN-6099-1

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
ncurses@6.3_p20221119-r0
6.3_p20221119-r1

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
yandex/clickhouse-server:21.3.204eccfffb01d7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1

Open the chart page →

9,250

Container images carrying it

810 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cockroachdb/cockroach:v22.2.91116820f4134
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
cockroachdb/cockroach-operator:v2.1.0983312754620
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
countly/countly-server:25.05.4e3c238248f99
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
craftypath/sops-operator:v0.8.0402a0024c732
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
cribl/cribl:3.0.2762747cb6796
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
ctron/hawkbit-operator:0.1.48fdea8f76499
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
daedalusproject/base_kubectl:latest6f72b5119eda
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
datalust/seq:5.0.832-pre9c731bb207a6
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
ncurses@6.1-7.20180224.el8
0:6.1-9.20180224.el8_8.1
1
davidvmar/urjc-davidvmar-rabbitmq:1.0.0e9ce2608f799
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
ncurses@6.3-2
6.3-2ubuntu0.1
1
dellcloud/category:distributed02fc234353a9
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
dellcloud/pages:1.04d2eb25b9225
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1
1
deluan/navidrome:0.49.311a24da08977
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
devopstales/trivy-operator:2.575136aa7a26e
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
dniel/api-posts:master45a667852f2a
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
dnsforge/xteve:latest4d9a685c8c28
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
dremio/dremio-oss:24.1.080ed2e3b7c43
ncurses@6.3-2
6.3-2ubuntu0.1
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
elastic/apm-server:7.17.6c7a1c63257d0
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
elastictranscoder/media:627e21dc963ab3858c6b
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
elastictranscoder/media-storage:f6d861a026208b8c2359
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
emqx/emqx:4.4.41d36535ba9de
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
engrmth/bnkr:2.1.06d8464e6f0e8
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.