StackRadar

CVE-2023-29491

High

Advisory

Published 14 Apr 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
810
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: ncurses security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 810 images.

Affected packageAffected versionsFixed inImages
ncursesdeb5.9+20140118-1ubuntu1, 6.0+20160213-1ubuntu1, 6.1-1ubuntu1, 6.1-1ubuntu1.18.04+2 more5.9+20140118-1ubuntu1+esm3, 6.0+20160213-1ubuntu1+esm3, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1+1 more443
ncursesapk6.3_p20211120-r0, 6.3_p20211120-r1, 6.3_p20220423-r0, 6.3_p20220521-r0+1 more6.3_p20211120-r2, 6.3_p20220521-r1, 6.3_p20221119-r1206
ncursesrpm6.1-7.20180224.el8, 6.1-9.20180224.el8, 6.1-9.20180224.el8_6.1, 6.1-150000.5.12.1+1 more0:6.1-9.20180224.el8_8.1, 0:6.2-10.20210508.el9, 6.1-150000.5.15.1161
OSV records
ALPINE-CVE-2023-29491RHSA-2023:5249RHSA-2023:6698UBUNTU-CVE-2023-29491SUSE-SU-2023:2111-1
Also known as
RHSA-2023:7361, RHSA-2024:0416, USN-6099-1

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
ncurses@6.3_p20221119-r0
6.3_p20221119-r1

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ncurses@6.1-9.20180224.el8
0:6.1-9.20180224.el8_8.1

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2023-29491.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
yandex/clickhouse-server:21.3.204eccfffb01d7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1

Open the chart page →

9,250

Container images carrying it

810 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jakuboskera/todo:v0.2.3714b1adbbc2d
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
jedi132000/nextapp:latestdc2a81e92f23
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
jmferrer/azure-devops-agent:latest030f68ec6998
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
kennethreitz/httpbin:latest599fe5e50731
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
kfirfer/scripts:0.0.2481e5c4e5d70e
ncurses@6.3_p20211120-r1
6.3_p20211120-r2
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
kubegems/kubectl:latestc3b4be9a54f5
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
ncurses@6.3_p20211120-r1
6.3_p20211120-r2
1
kudobuilder/controller:v0.9.069072d979708
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
kyso/kyso-nbdime:latest4aa9d38ee81d
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
library/cassandra:3.11.10b095ff3248c6
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/docker:20.10.21-dind3153fa63f546
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
library/docker:23.0.1-dindd9a0fd8bdd15
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
library/elasticsearch:7.17.0332c6d416808
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/elasticsearch:7.17.8fdc73b3249c1
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/flink:1.14.6-scala_2.122461f02672b3
ncurses@6.3-2
6.3-2ubuntu0.1
1
library/kibana:7.17.8c5781ba340ef
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/kibana:7.17.3e2e2031c15be
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/logstash:7.17.817a4f64e9cf5
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mariadb:10.7.307e06f2e7ae9
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mariadb:10.11.21c33370a599c
ncurses@6.3-2
6.3-2ubuntu0.1
1
library/mariadb:10.8.2-focal490f01279be1
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mariadb:10.79a48ac9f196f
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mariadb:10.10.2bfc25a68e113
ncurses@6.3-2
6.3-2ubuntu0.1
1
library/mariadb:10.9.4fbb8456ebdb1
ncurses@6.3-2
6.3-2ubuntu0.1
1
library/mongo:4.4.1305678ae4e5e1
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mongo:3.6146c1fd999a6
ncurses@6.0+20160213-1ubuntu1
6.0+20160213-1ubuntu1+esm3
1
library/mongo:4.4-bionic3d0e6df9fd5b
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
library/mongo:5.0.14-focal50cae5081ab4
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mongo:4.2.16ca49afbcb2b
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
library/mongo:6.0.271a63fc2438e
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/mongo:4.2.21-bionic9cb28f7291d9
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
library/mongo:4.4.18d23ec07162ca
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/nginx:1.23.2-alpine455c39afebd4
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
library/php:7-fpm-alpine0aeb129a60da
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
library/postgres:12.14-alpine3.174b100eafe128
ncurses@6.3_p20221119-r0
6.3_p20221119-r1
1
library/postgres:14.1-alpine578ca5c8452c
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
library/postgres:13.6-alpine8522c9920d88
ncurses@6.3_p20211120-r0
6.3_p20211120-r2
1
library/rabbitmq:3.11.5-management1b0f675d2f24
ncurses@6.2-0ubuntu2
6.2-0ubuntu2.1
1
library/rabbitmq:3.8.34-alpine711d76bc8d98
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1
library/rabbitmq:3.7-managementb6dd45cc35b3
ncurses@6.1-1ubuntu1.18.04
6.1-1ubuntu1.18.04.1
1
library/rabbitmq:3.8-management-alpinec3e526769bfd
ncurses@6.3_p20220521-r0
6.3_p20220521-r1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.