StackRadar

CVE-2023-2976

Medium

Advisory

Published 14 Jun 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
379
of 17,781 indexed, latest versions
Container images
410
deployed by those charts
Fix available
1 of 1
affected package

Guava vulnerable to insecure use of temporary directory

Carried by container images the latest versions of 379 of 17,781 indexed charts deploy, on 410 images.

Affected packageAffected versionsFixed inImages
guavamaven10.0.1, 11.0.1, 11.0.2, 14.0+38 more32.0.0-android410
OSV records
GHSA-7g45-4rm6-3mm3

Charts affected

379 by stars
ChartLatestAffected imagesRadar Score
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
guava@28.1-jre
32.0.0-android

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
guava@10.0.1
32.0.0-android

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
guava@31.0.1-jre
32.0.0-android

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
guava@31.0.1-jre
32.0.0-android

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
guava@19.0
32.0.0-android

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
guava@25.1-jre
32.0.0-android

Open the chart page →

18,756
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
guava@19.0
32.0.0-android

Open the chart page →

4,538
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
guava@30.1.1-jre
32.0.0-android

Open the chart page →

4,240
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

21,005
shenyutest-helm2.4.212 of 2See more

shenyu test-helm 2.4.21

2 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
guava@31.0.1-jre
32.0.0-android
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
guava@24.1.1-jre
32.0.0-android

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
guava@30.0-jre
32.0.0-android
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
guava@30.0-jre
32.0.0-android
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
guava@30.0-jre
32.0.0-android
thingsboard/tb-node:3.4.1645f43b688f7
guava@30.0-jre
32.0.0-android

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
guava@30.1-jre
32.0.0-android

Open the chart page →

12,455
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
guava@22.0
32.0.0-android

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
guava@22.0
32.0.0-android

Open the chart page →

3,176
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
guava@29.0-android
32.0.0-android

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
guava@26.0-jre
32.0.0-android

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
guava@30.1-jre
32.0.0-android

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android

Open the chart page →

22,665
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
guava@27.0-jre
32.0.0-android

Open the chart page →

9,248
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
guava@29.0-jre
32.0.0-android

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
guava@28.2-jre
32.0.0-android

Open the chart page →

5,806
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
guava@28.1-jre
32.0.0-android

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
guava@27.0.1-jre
32.0.0-android

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
guava@31.1-jre
32.0.0-android

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
guava@31.1-jre
32.0.0-android

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-2976.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
guava@30.1-jre
32.0.0-android

Open the chart page →

6,016

Container images carrying it

410 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codeurjc/server:v1.0310bea5b1ee7
guava@31.0.1-jre
32.0.0-android
8
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
guava@24.0-jre
32.0.0-android
8
gradiant/hdfs:2.7.73b28784ba41f
guava@11.0.2
32.0.0-android
7
library/cassandra:3.11.3ce85468c5bad
guava@18.0
32.0.0-android
7
bde2020/hive:2.3.2-postgresql-metastore620267768985
guava@11.0.2
32.0.0-android
4
gradiant/hbase-base:2.0.1a1ee6de94c04
guava@11.0.2
32.0.0-android
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
guava@27.0-jre
32.0.0-android
4
mastercloudapps/planner:v1.2340a950b311b2
guava@28.1-android
32.0.0-android
4
mastercloudapps/server:v2.23f3d24dfe2686
guava@31.0.1-jre
32.0.0-android
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
guava@31.0.1-jre
32.0.0-android
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
guava@24.1.1-jre
32.0.0-android
3
codeurjc/planner:v1.0800cf520c245
guava@28.1-android
32.0.0-android
3
gchq/hdfs:3.3.35ec58edbb2db
guava@30.1.1-jre
32.0.0-android
3
library/solr:8.11.18c5f7881cebb
guava@25.0-jre
32.0.0-android
3
lmenezes/cerebro:0.9.47d9e2b77e459
guava@28.2-jre
32.0.0-android
3
mockserver/mockserver:5.15.0:mockserver-5.15.00f9ef78c9489
guava@31.1-jre
32.0.0-android
3
provectuslabs/kafka-ui:latest8f2ff02d64b0
guava@30.1.1-jre
32.0.0-android
3
selenium/hub:3.141.5902f251d48d5f
guava@25.0-jre
32.0.0-android
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
guava@28.2-jre
32.0.0-android
2
apache/druid:37.0.00116fb802786
guava@14.0.1
32.0.0-android
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
guava@11.0.2
32.0.0-android
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
guava@29.0-jre
32.0.0-android
2
danisla/hadoop:2.9.0255ba2dd739b
guava@11.0.2
32.0.0-android
2
dependencytrack/apiserver:4.6.3485ac0952c02
guava@31.1-jre
32.0.0-android
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
guava@19.0
32.0.0-android
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
guava@29.0-jre
32.0.0-android
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
guava@29.0-jre
32.0.0-android
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
guava@29.0-jre
32.0.0-android
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
guava@29.0-jre
32.0.0-android
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
guava@29.0-jre
32.0.0-android
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
guava@29.0-jre
32.0.0-android
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
guava@11.0.2
32.0.0-android
2
gradiant/opentsdb:2.4.0c33d53913869
guava@18.0
32.0.0-android
2
gradiant/spark:2.4.4-python-alpine97657d56e927
guava@14.0.1
32.0.0-android
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
guava@30.0-jre
32.0.0-android
2
library/cassandra:3.11.65aa8400b4b3b
guava@18.0
32.0.0-android
2
library/cassandra:4.1.37cbcec0086ac
guava@27.0-jre
32.0.0-android
2
library/elasticsearch:7.17.35e6ac15bf6a5
guava@19.0
32.0.0-android
2
library/neo4j:4.3.2-enterprise56a9453c4064
guava@20.0
32.0.0-android
2
mbentley/omada-controller:4.3f4e682274bed
guava@27.0.1-jre
32.0.0-android
2
metabase/metabase:v0.45.21fb334ce4820
guava@31.0.1-jre
32.0.0-android
2
nacos/nacos-server:v2.1.0dcf04549c6d7
guava@30.1-jre
32.0.0-android
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
guava@30.1.1-android
32.0.0-android
2
opensearchproject/opensearch:2.1.04254021a8c71
guava@31.0.1-jre
32.0.0-android
2
opensearchproject/opensearch:1.1.0967d7f57f72f
guava@29.0-jre
32.0.0-android
2
rodolpheche/wiremock:2.26.03be08a386092
guava@27.0.1-jre
32.0.0-android
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
guava@29.0-jre
32.0.0-android
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
guava@19.0
32.0.0-android
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
guava@29.0-jre
32.0.0-android
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
guava@19.0
32.0.0-android
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.