StackRadar

CVE-2023-2976

Medium

Advisory

Published 14 Jun 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
379
of 17,781 indexed, latest versions
Container images
410
deployed by those charts
Fix available
1 of 1
affected package

Guava vulnerable to insecure use of temporary directory

Carried by container images the latest versions of 379 of 17,781 indexed charts deploy, on 410 images.

Affected packageAffected versionsFixed inImages
guavamaven10.0.1, 11.0.1, 11.0.2, 14.0+38 more32.0.0-android410
OSV records
GHSA-7g45-4rm6-3mm3

Charts affected

379 by stars
ChartLatestAffected imagesRadar Score
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
guava@28.1-jre
32.0.0-android

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
guava@10.0.1
32.0.0-android

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
guava@31.0.1-jre
32.0.0-android

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
guava@31.0.1-jre
32.0.0-android

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
guava@19.0
32.0.0-android

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
guava@25.1-jre
32.0.0-android

Open the chart page →

18,756
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
guava@19.0
32.0.0-android

Open the chart page →

4,538
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
guava@30.1.1-jre
32.0.0-android

Open the chart page →

4,240
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

21,005
shenyutest-helm2.4.212 of 2See more

shenyu test-helm 2.4.21

2 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
guava@31.0.1-jre
32.0.0-android
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
guava@24.1.1-jre
32.0.0-android

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
guava@30.0-jre
32.0.0-android
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
guava@30.0-jre
32.0.0-android
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
guava@30.0-jre
32.0.0-android
thingsboard/tb-node:3.4.1645f43b688f7
guava@30.0-jre
32.0.0-android

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
guava@30.1-jre
32.0.0-android

Open the chart page →

12,455
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
guava@22.0
32.0.0-android

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
guava@22.0
32.0.0-android

Open the chart page →

3,176
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
guava@29.0-android
32.0.0-android

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
guava@26.0-jre
32.0.0-android

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
guava@30.1-jre
32.0.0-android

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

22,665
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
guava@27.0-jre
32.0.0-android

Open the chart page →

9,248
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
guava@29.0-jre
32.0.0-android

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
guava@28.2-jre
32.0.0-android

Open the chart page →

5,806
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
guava@28.1-jre
32.0.0-android

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
guava@27.0.1-jre
32.0.0-android

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
guava@31.1-jre
32.0.0-android

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
guava@31.1-jre
32.0.0-android

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
guava@30.1-jre
32.0.0-android

Open the chart page →

6,016

Container images carrying it

410 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hivemq/hivemq-operator:4.7.10241d6a8e1963
guava@25.0-jre
32.0.0-android
1
housewrecker/gaps:latestf417dd0a7547
guava@31.0.1-jre
32.0.0-android
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
guava@28.1-android
32.0.0-android
1
hugohg34/planner:0.0.2171f61e8d7e2
guava@28.1-android
32.0.0-android
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
guava@25.1-jre
32.0.0-android
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
guava@18.0
32.0.0-android
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
guava@25.1-jre
32.0.0-android
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
guava@22.0-android
32.0.0-android
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
guava@20.0
32.0.0-android
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
guava@20.0
32.0.0-android
1
ibmcom/microclimate-theia:lateste17bdccc5030
guava@18.0
32.0.0-android
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
guava@30.1.1-jre
32.0.0-android
1
jacobalberty/unifi:v7.1.664a3616625dda
guava@31.0.1-jre
32.0.0-android
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
guava@31.0.1-jre
32.0.0-android
1
jacobalberty/unifi:5.10.19c409924e2463
guava@26.0-jre
32.0.0-android
1
jenkinsci/jenkins:2.67a1f33f004659
guava@11.0.1
32.0.0-android
1
jhipster/jhipster-registry:latest7184525acd4d
guava@31.1-jre
32.0.0-android
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
guava@30.0-jre
32.0.0-android
1
just1not2/streama:1.10.48a2305192dec
guava@19.0
32.0.0-android
1
keyfactor/signserver-ce:7.3.2798fbbe00283
guava@25.0-jre
32.0.0-android
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
guava@29.0-android
32.0.0-android
1
kubebb/gateway-api:v5.6.04d062f20309c
guava@29.0-jre
32.0.0-android
1
kyso/imagebox:latest68091eace89c
guava@27.1-jre
32.0.0-android
1
ladeit/ladeit:latest962b665ffe82
guava@18.0
32.0.0-android
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
guava@30.0-jre
32.0.0-android
1
library/cassandra:4.0093ee8ee5eb2
guava@27.0-jre
32.0.0-android
1
library/cassandra:3.11.598531a31f213
guava@18.0
32.0.0-android
1
library/cassandra:3.11.10b095ff3248c6
guava@18.0
32.0.0-android
1
library/cassandra:2.1.20cb079c0d7a57
guava@16.0
32.0.0-android
1
library/crate:4.7.0c7984a05e15b
guava@30.0-jre
32.0.0-android
1
library/elasticsearch:7.17.0332c6d416808
guava@27.1-jre
32.0.0-android
1
library/elasticsearch:2.4.641ed3a1a16b6
guava@18.0
32.0.0-android
1
library/elasticsearch:7.17.1588c2ec10c7f2
guava@19.0
32.0.0-android
1
library/elasticsearch:7.17.8fdc73b3249c1
guava@19.0
32.0.0-android
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
guava@26.0-jre
32.0.0-android
1
library/logstash:7.17.817a4f64e9cf5
guava@24.1.1-jre
32.0.0-android
1
library/solr:8.7.0d124efd81fbb
guava@25.0-jre
32.0.0-android
1
library/sonarqube:6.7.6-community0ae5169e3d0f
guava@10.0.1
32.0.0-android
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
guava@10.0.1
32.0.0-android
1
library/sonarqube:8.9.2-community88cd63154d4b
guava@30.1.1-jre
32.0.0-android
1
library/sonarqube:8.2-communitya246bc64207e
guava@26.0-jre
32.0.0-android
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
guava@28.2-jre
32.0.0-android
1
library/sonarqube:8.9-communityeb2f0be32efd
guava@30.1.1-jre
32.0.0-android
1
library/sonarqube:10.0.0-communityef9723cf4fe4
guava@28.2-jre
32.0.0-android
1
library/storm:2.4.0bd5d420506d6
guava@27.0.1-jre
32.0.0-android
1
library/zookeeper:3.43882d9493d38
guava@18.0
32.0.0-android
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
guava@11.0.2
32.0.0-android
1
lightbend/spark-history-server:2.4.00bedf37f428a
guava@14.0.1
32.0.0-android
1
linuxserver/unifi-controller:8.0.240ae315a3a456
guava@31.0.1-jre
32.0.0-android
1
linuxserver/unifi-controller:7.3.83ab105cc50322
guava@31.0.1-jre
32.0.0-android
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.