StackRadar

CVE-2023-2975

Medium

Advisory

Published 14 Jul 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,781 indexed, latest versions
Container images
359
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 362 of 17,781 indexed charts deploy, on 359 images.

Affected packageAffected versionsFixed inImages
opensslapk3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+5 more3.0.9-r2, 3.1.1-r2225
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+6 more3.0.2-0ubuntu1.12, 3.0.2-0ubuntu1.12+Fips1, 3.0.10-1~deb12u1132
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
OSV records
ALPINE-CVE-2023-2975DEBIAN-CVE-2023-2975UBUNTU-CVE-2023-2975
Also known as
USN-6450-1

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1

Open the chart page →

9,248
wiremind-baremetalwiremindVerified publisher2.0.21 of 1See more

wiremind-baremetal wiremind 2.0.2

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
library/alpine:3.18.002bb6f428431
openssl@3.1.0-r4
3.1.1-r2

Open the chart page →

487
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100
oauth2xdVerified publisher1.0.01 of 1See more

oauth2 xd 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/hufu:v1.2.13d5752dac834
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

2,007
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
openssl@3.0.8-r0
3.0.9-r2
lishimeng/owl-messager:v0.11.23d00485e64dc
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
openssl@3.0.8-r0
3.0.9-r2
lishimeng/passport-profile:v0.2.160970dfe5dc8f
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

7,673
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
openssl@3.0.8-r0
3.0.9-r2

Open the chart page →

1,955
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
openssl@3.0.9-r1
3.0.9-r2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
openssl@3.0.9-r1
3.0.9-r2

Open the chart page →

5,033
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
openssl@3.1.1-r1
3.1.1-r2

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-2975.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.9-r2
zahoriaut/zahori-server:0.1.17b2de13916f3e
openssl@3.0.8-r3
3.0.9-r2

Open the chart page →

5,846

Container images carrying it

359 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/registry:2.8.1dbaa3e69f563
openssl@3.1.0-r4
3.1.1-r2
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
openssl@3.1.0-r4
3.1.1-r2
6
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.12+Fips1
4
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.12
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
openssl@3.1.1-r1
3.1.1-r2
4
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.12
3
library/docker:20.10-dind:20-dindaf96c680a7e1
openssl@3.1.0-r4
3.1.1-r2
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
openssl@3.1.1-r1
3.1.1-r2
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
openssl@3.0.8-r3
3.0.9-r2
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
openssl@3.0.9-1
3.0.10-1~deb12u1
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.12
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.12
3
quay.io/metallb/controller:v0.13.101b33357b3595
openssl@3.1.0-r4
3.1.1-r2
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
openssl@3.1.1-r1
3.1.1-r2
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
openssl@3.0.8-r3
3.0.9-r2
2
cs3org/wopiserver:v9.4.202a9e78757b4
openssl@3.0.8-r0
3.0.9-r2
2
daniacobext/airports-frontend:latest9eae4d39fc33
openssl@3.0.9-r1
3.0.9-r2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssl@3.0.9-1
3.0.10-1~deb12u1
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
openssl@3.0.9-1
3.0.10-1~deb12u1
2
istio/proxyv2:1.18.0757d28c24100
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.12
2
krtk6160/galoy-nostrcc82a694f818
openssl@3.0.8-r0
3.0.9-r2
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
openssl@3.0.7-r0
3.0.9-r2
2
library/influxdb:2.6.1-alpine44a366dd7724
openssl@3.0.8-r3
3.0.9-r2
2
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
2
library/nats:2.9.17-alpine1a7b320b2942
openssl@3.1.0-r4
3.1.1-r2
2
library/postgres:15.2-alpined9c304353c03
openssl@3.0.8-r3
3.0.9-r2
2
library/python:3.7eedf63967cdb
openssl@3.0.9-1
3.0.10-1~deb12u1
2
library/rabbitmq:3.12.1-managementf020c06da226
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.12
2
metabase/metabase:v0.45.21fb334ce4820
openssl@3.0.7-r2
3.0.9-r2
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
openssl@3.0.7-r2
3.0.9-r2
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
openssl@3.0.8-r3
3.0.9-r2
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.12
2
openebs/node-disk-operator:2.1.06afe2123c457
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.12
2
oryd/kratos:v1.0.0d06fc5845f63
openssl@3.1.1-r1
3.1.1-r2
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
openssl@3.1.1-r1
3.1.1-r2
2
outlinewiki/outline:0.69.1d060dcd8f9aa
openssl@3.0.8-r3
3.0.9-r2
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
2
shahanafarooqui/rtl:0.13.3e2195188a451
openssl@3.0.7-r0
3.0.9-r2
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssl@3.0.2-0ubuntu1.5
3.0.2-0ubuntu1.12
2
taigaio/taiga-front:latest570c8792ce80
openssl@3.0.8-r3
3.0.9-r2
2
temporalio/ui:2.16.2af9c9349708f
openssl@3.1.1-r1
3.1.1-r2
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nodejs@16.14.2-deb-1nodesource1
openssl@3.0.2-0ubuntu1.9
no fix listed
3.0.2-0ubuntu1.12
2
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
openssl@3.0.8-r3
3.0.9-r2
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.12
2
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
openssl@3.0.7-r0
3.0.9-r2
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.12
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
openssl@3.0.8-r0
3.0.9-r2
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
openssl@3.1.0-r4
3.1.1-r2
2
0hlov3/semaphore:v1.0.050f874ec096b
openssl@3.0.8-r0
3.0.9-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.