StackRadar

CVE-2023-2975

Medium

Advisory

Published 14 Jul 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,787 indexed, latest versions
Container images
359
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 362 of 17,787 indexed charts deploy, on 359 images.

Affected packageAffected versionsFixed inImages
opensslapk3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+5 more3.0.9-r2, 3.1.1-r2225
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+6 more3.0.2-0ubuntu1.12, 3.0.2-0ubuntu1.12+Fips1, 3.0.10-1~deb12u1132
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
OSV records
ALPINE-CVE-2023-2975DEBIAN-CVE-2023-2975UBUNTU-CVE-2023-2975
Also known as
USN-6450-1

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1

Open the chart page →

9,248
wiremind-baremetalwiremindVerified publisher2.0.21 of 1See more

wiremind-baremetal wiremind 2.0.2

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
library/alpine:3.18.002bb6f428431
openssl@3.1.0-r4
3.1.1-r2

Open the chart page →

487
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100
oauth2xdVerified publisher1.0.01 of 1See more

oauth2 xd 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/hufu:v1.2.13d5752dac834
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

2,007
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
openssl@3.0.8-r0
3.0.9-r2
lishimeng/owl-messager:v0.11.23d00485e64dc
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
openssl@3.0.8-r0
3.0.9-r2
lishimeng/passport-profile:v0.2.160970dfe5dc8f
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

7,673
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

1,955
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
openssl@3.0.9-r1
3.0.9-r2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
openssl@3.0.9-r1
3.0.9-r2

Open the chart page →

5,033
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
openssl@3.1.1-r1
3.1.1-r2

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.9-r2
zahoriaut/zahori-server:0.1.17b2de13916f3e
openssl@3.0.8-r3
3.0.9-r2

Open the chart page →

5,846

Container images carrying it

359 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1
1
ghcr.io/cosmo-workspace/cosmo-traefik-plugins:v0.9.1435518f49e23
openssl@3.1.0-r4
3.1.1-r2
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
openssl@3.0.8-r0
3.0.9-r2
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1
1
ghcr.io/data-fair/metrics:0a8d40779eeae
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/data-fair/portals:18b621866ceb2
openssl@3.0.8-r3
3.0.9-r2
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
openssl@3.0.8-r0
3.0.9-r2
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.12
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
openssl@3.1.1-r1
3.1.1-r2
1
ghcr.io/k10app/businit:latest94c9a3e799c2
openssl@3.0.7-r0
3.0.9-r2
1
ghcr.io/k10app/order:lateste1017d0dbd78
openssl@3.0.7-r0
3.0.9-r2
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
1
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
openssl@3.0.9-1
3.0.10-1~deb12u1
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
1
ghcr.io/liubin/toml-cli:v0.0.734a1da9f0f83
openssl@3.0.7-r0
3.0.9-r2
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
openssl@3.0.8-r0
3.0.9-r2
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
openssl@3.0.8-r0
3.0.9-r2
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
openssl@3.0.8-r0
3.0.9-r2
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
openssl@3.1.0-r4
3.1.1-r2
1
ghcr.io/pascaliske/traefik-errors:1.1.00cf31753ce57
openssl@3.0.9-r1
3.0.9-r2
1
ghcr.io/pascaliske/unbound:0.1.09009fbd2ef16
openssl@3.0.7-r0
3.0.9-r2
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1
1
ghcr.io/rivals-space/rivals-nginx:1.6.1f376b96b82cc
openssl@3.0.7-r2
3.0.9-r2
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
openssl@3.0.9-1
3.0.10-1~deb12u1
1
ghcr.io/schildichat/schildichat-web:latesta87f57287805
openssl@3.0.8-r3
3.0.9-r2
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
openssl@3.0.9-1
3.0.10-1~deb12u1
1
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
openssl@3.0.8-r3
3.0.9-r2
1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
openssl@3.0.8-r3
3.0.9-r2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.12
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
openssl@3.1.0-r4
3.1.1-r2
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
openssl@3.0.7-r2
3.0.9-r2
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
openssl@3.1.0-r4
3.1.1-r2
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.12
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
openssl@3.1.1-r1
3.1.1-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.