CVE-2023-2975
MediumAdvisory
Published 14 Jul 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.006
- 48th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 362
- of 17,787 indexed, latest versions
- Container images
- 359
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 362 of 17,787 indexed charts deploy, on 359 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+5 more | 3.0.9-r2, 3.1.1-r2 | 225 |
| openssldeb | 3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+6 more | 3.0.2-0ubuntu1.12, 3.0.2-0ubuntu1.12+Fips1, 3.0.10-1~deb12u1 | 132 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
- OSV records
- ALPINE-CVE-2023-2975DEBIAN-CVE-2023-2975UBUNTU-CVE-2023-2975
- Also known as
- USN-6450-1
Charts affected
362 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| jaegerwikimedia | 3.1.2 | 1 of 4See more | 9,248 |
| wiremind-baremetalwiremindVerified publisher | 2.0.2 | 1 of 1See more | 487 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,100 |
| oauth2xdVerified publisher | 1.0.0 | 1 of 1See more | 2,007 |
| owlxdVerified publisher | 0.5.1 | 2 of 2See more | 3,880 |
| passportxdVerified publisher | 0.2.16 | 2 of 2See more | 3,974 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,673 |
| treexdVerified publisher | 0.1.10 | 1 of 1See more | 1,997 |
| zooxdVerified publisher | 0.4.0 | 1 of 1See more | 1,955 |
| zahori-consulzahoriVerified publisher | 1.0.1 | 2 of 2See more | 5,033 |
| zahori-processzahoriVerified publisher | 1.0.1 | 1 of 1See more | 3,480 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 2 of 2See more | 5,846 |
Container images carrying it
359 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | ed8f5118e3a4 | openssl | 3.0.9-r2 | 1 |
| quay.io/ | 80ddeb90d18d | openssl | 3.0.9-r2 | 1 |
| quay.io/ | 476ae867ae56 | openssl | 3.0.9-r2 | 1 |
| quay.io/ | defc3263e0e9 | openssl | 3.0.9-r2 | 1 |
| quay.io/ | 5b986cd14a08 | openssl | 3.0.9-r2 | 1 |
| quay.io/ | e0d9b93dbf2b | openssl | 3.0.10-1~deb12u1 | 1 |
| registry.k8s.io/ | 15be4666c530 | openssl | 3.0.9-r2 | 1 |
| registry.k8s.io/ | 744ae2afd433 | openssl | 3.1.1-r2 | 1 |
| registry.k8s.io/ | 7612338342a1 | openssl | 3.0.9-r2 | 1 |