StackRadar

CVE-2023-2976

Medium

Advisory

Published 14 Jun 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
379
of 17,781 indexed, latest versions
Container images
410
deployed by those charts
Fix available
1 of 1
affected package

Guava vulnerable to insecure use of temporary directory

Carried by container images the latest versions of 379 of 17,781 indexed charts deploy, on 410 images.

Affected packageAffected versionsFixed inImages
guavamaven10.0.1, 11.0.1, 11.0.2, 14.0+38 more32.0.0-android410
OSV records
GHSA-7g45-4rm6-3mm3

Charts affected

379 by stars
ChartLatestAffected imagesRadar Score
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
guava@28.1-jre
32.0.0-android

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
guava@10.0.1
32.0.0-android

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
guava@31.0.1-jre
32.0.0-android

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
guava@31.0.1-jre
32.0.0-android

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
guava@19.0
32.0.0-android

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
guava@25.1-jre
32.0.0-android

Open the chart page →

18,756
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
guava@19.0
32.0.0-android

Open the chart page →

4,538
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
guava@30.1.1-jre
32.0.0-android

Open the chart page →

4,240
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

21,005
shenyutest-helm2.4.212 of 2See more

shenyu test-helm 2.4.21

2 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
guava@31.0.1-jre
32.0.0-android
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
guava@24.1.1-jre
32.0.0-android

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
guava@30.0-jre
32.0.0-android
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
guava@30.0-jre
32.0.0-android
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
guava@30.0-jre
32.0.0-android
thingsboard/tb-node:3.4.1645f43b688f7
guava@30.0-jre
32.0.0-android

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
guava@30.1-jre
32.0.0-android

Open the chart page →

12,455
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
guava@22.0
32.0.0-android

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
guava@22.0
32.0.0-android

Open the chart page →

3,176
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
guava@29.0-android
32.0.0-android

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
guava@26.0-jre
32.0.0-android

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
guava@30.1-jre
32.0.0-android

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

22,665
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
guava@27.0-jre
32.0.0-android

Open the chart page →

9,248
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
guava@29.0-jre
32.0.0-android

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
guava@28.2-jre
32.0.0-android

Open the chart page →

5,806
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
guava@28.1-jre
32.0.0-android

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
guava@27.0.1-jre
32.0.0-android

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
guava@31.1-jre
32.0.0-android

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
guava@31.1-jre
32.0.0-android

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
guava@30.1-jre
32.0.0-android

Open the chart page →

6,016

Container images carrying it

410 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/skywalking-oap-server:8.9.1b4ec8c18d079
guava@28.1-jre
32.0.0-android
1
apache/skywalking-ui:8.1.067d50e4deff4
guava@18.0
32.0.0-android
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
guava@29.0-jre
32.0.0-android
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
guava@30.1-jre
32.0.0-android
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
guava@31.0.1-jre
32.0.0-android
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
guava@31.0.1-jre
32.0.0-android
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
guava@31.0.1-jre
32.0.0-android
1
arturisimo/planner:v1.0fff9de644941
guava@28.1-android
32.0.0-android
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
guava@15.0
32.0.0-android
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
guava@18.0
32.0.0-android
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
guava@27.1-jre
32.0.0-android
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
guava@30.1.1-jre
32.0.0-android
1
assistiot/identity-manager_kc:latest0df4b4fa899a
guava@31.1-jre
32.0.0-android
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
guava@22.0
32.0.0-android
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
guava@31.1-jre
32.0.0-android
1
atlassian/confluence-server:7.10.03b9222ab32ef
guava@26.0-jre
32.0.0-android
1
atlassian/crowd:5.2.2ebf761c7d437
guava@31.1-jre
32.0.0-android
1
atlassian/jira-software:8.14.037bc46cbec1a
guava@26.0-jre
32.0.0-android
1
atlassian/jira-software:9.7.264a75aa4ec4e
guava@19.0
32.0.0-android
1
atomix/atomix:3.1.127738ff4f5c63
guava@22.0
32.0.0-android
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
guava@20.0
32.0.0-android
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
guava@27.0-jre
32.0.0-android
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
guava@30.1-jre
32.0.0-android
1
bivas/presto:0.19605545994f806
guava@21.0
32.0.0-android
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
guava@31.1-jre
32.0.0-android
1
choerodon/event-store-service:0.8.03c94c97f6f69
guava@18.0
32.0.0-android
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
guava@28.1-jre
32.0.0-android
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
guava@28.1-jre
32.0.0-android
1
confluentinc/cp-kafka:5.4.01bbda887bc53
guava@20.0
32.0.0-android
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
guava@11.0.2
32.0.0-android
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
guava@28.1-jre
32.0.0-android
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
guava@28.1-jre
32.0.0-android
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
guava@28.1-jre
32.0.0-android
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
guava@28.1-jre
32.0.0-android
1
craigwillis/c2metadata-bd:latestae317d7e4724
guava@20.0
32.0.0-android
1
datappeal/hive-metastore:lateste38c085a3567
guava@11.0.2
32.0.0-android
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
guava@28.1-android
32.0.0-android
1
dbanda/livy:0.80ca125e68e53
guava@15.0
32.0.0-android
1
dbanda/spark:2.4.6d0e6367876ae
guava@27.0-jre
32.0.0-android
1
deltaio/delta-sharing-server:0.2.08b75118187c5
guava@14.0.1
32.0.0-android
1
dniel/api-posts:master45a667852f2a
guava@27.1-jre
32.0.0-android
1
dniel/forwardauth:latestf67129ea1c64
guava@27.0.1-jre
32.0.0-android
1
dremio/dremio-oss:24.1.080ed2e3b7c43
guava@30.1.1-jre
32.0.0-android
1
duck1123/dinsro:latest9568c5961d5d
guava@31.1-android
32.0.0-android
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
guava@31.0.1-android
32.0.0-android
1
easypi/openrefine:3.7.0d2950a36a576
guava@31.0.1-jre
32.0.0-android
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
guava@25.1-jre
32.0.0-android
1
emcniece/dockeryourxyzzy:404eccbccc15c
guava@20.0
32.0.0-android
1
emeraldpay/dshackle:0.14.0126f0ae0b388
guava@30.1-android
32.0.0-android
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
guava@30.1-android
32.0.0-android
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.