StackRadar

CVE-2023-3138

High

Advisory

Published 15 Jun 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.017
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
462
of 17,781 indexed, latest versions
Container images
419
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libX11 security update

Carried by container images the latest versions of 462 of 17,781 indexed charts deploy, on 419 images.

Affected packageAffected versionsFixed inImages
libx11deb2:1.6.2-1ubuntu2, 2:1.6.2-1ubuntu2.1, 2:1.6.3-1ubuntu2, 2:1.6.3-1ubuntu2.1+12 more2:1.6.2-1ubuntu2.1+esm3, 2:1.6.3-1ubuntu2.2+esm2, 2:1.6.4-3ubuntu0.4+esm1, 2:1.6.7-1+deb10u3+4 more356
libx11apk1.7.2-r0, 1.7.3.1-r0, 1.8-r0, 1.8.3-r0+2 more1.7.3.1-r1, 1.8-r1, 1.8.4-r139
libX11rpm1.6.8-3.el8, 1.6.8-4.el8, 1.6.8-5.el8, 1.7.0-7.el90:1.6.8-6.el8, 0:1.7.0-8.el924
OSV records
ALPINE-CVE-2023-3138DEBIAN-CVE-2023-3138RHSA-2023:6497RHSA-2023:7029UBUNTU-CVE-2023-3138DLA-3472-1DSA-5433-1
Also known as
RHSA-2024:1088, RHSA-2024:1417, USN-6168-1, USN-6168-2

Charts affected

462 by stars
ChartLatestAffected imagesRadar Score
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1

Open the chart page →

3,392
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libx11@2:1.6.9-2ubuntu1.2
2:1.6.9-2ubuntu1.5

Open the chart page →

11,405
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1

Open the chart page →

2,132
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3

Open the chart page →

2,670
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1

Open the chart page →

7,552
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1

Open the chart page →

2,021
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3

Open the chart page →

16,083
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libX11@1.6.8-5.el8
0:1.6.8-6.el8

Open the chart page →

11,577
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-3138.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3

Open the chart page →

1,138

Container images carrying it

419 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jakowenko/double-take:1.6.0b858bac9e32a
libx11@2:1.6.9-2ubuntu1.2
2:1.6.9-2ubuntu1.5
1
jedi132000/nextapp:latestdc2a81e92f23
libx11@2:1.6.9-2ubuntu1.2
2:1.6.9-2ubuntu1.5
1
jellyfin/jellyfin:10.8.1ee24f4459a40
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
julb/http-url-playlist:1.0.2782ef45279d5
libx11@2:1.6.7-1+deb10u1
2:1.6.7-1+deb10u3
1
kobotoolbox/kobocat:2.022.24ab15679454415
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
kubebb/hello-world:0.1.0b746824819f3
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
ldapaccountmanager/lam:7.295533a96a4c1
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3
1
library/nextcloud:17.0.0-apache96104cb965fc
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3
1
library/nginx:1.23.03536d368b898
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
library/nginx:1.19.68e1095642250
libx11@2:1.6.7-1+deb10u1
2:1.6.7-1+deb10u3
1
library/nginx:1.23.2ab589a3c466e
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
library/nginx:1.17.6b2d89d0a2103
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3
1
library/nginx:1.16.1d20aa6d1cae5
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3
1
library/nginx:1.23.3f4e3b6489888
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
library/nginx:1.23f5747a42e3ad
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
librenms/librenms:22.4.14f1f3d667cc7
libx11@1.7.2-r0
1.7.3.1-r1
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libx11@2:1.6.4-3ubuntu0.4
2:1.6.4-3ubuntu0.4+esm1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libx11@2:1.6.9-2ubuntu1.2
2:1.6.9-2ubuntu1.5
1
linuxserver/code-server:4.10.1a5e43a05ae79
libx11@2:1.7.5-1
2:1.7.5-1ubuntu0.2
1
linuxserver/jellyfin:10.7.72427dde159a2
libx11@2:1.6.9-2ubuntu1.2
2:1.6.9-2ubuntu1.5
1
liukunup/jmeter:5.59c079617a81b
libx11@1.8-r0
1.8-r1
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3
1
lsstsqre/kafkaaggregator:masterbe1b21060854
libx11@2:1.6.7-1+deb10u1
2:1.6.7-1+deb10u3
1
lsstsqre/squash-api:0.5.34879415ec6ac
libx11@2:1.6.7-1+deb10u1
2:1.6.7-1+deb10u3
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
maissacrement/pock8snodejs:0.0.16da0db1159da
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
libx11@1.8-r0
1.8-r1
1
misskey/misskey:12.110.1e08b7c478093
libx11@1.7.2-r0
1.7.3.1-r1
1
mnaggar3396/python-app:latest371d8ed84b15
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3
1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
libx11@2:1.6.7-1
2:1.6.7-1+deb10u3
1
mshanley80/httpbin2022:latest5b189a70c0fb
libx11@2:1.6.9-2ubuntu1.2
2:1.6.9-2ubuntu1.5
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libx11@2:1.6.3-1ubuntu2
2:1.6.3-1ubuntu2.2+esm2
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
nethermind/nethermind:1.14.615517708c3b6
libx11@2:1.7.5-1
2:1.7.5-1ubuntu0.2
1
nginx/nginx-ingress:1.11.1eb5b4fd73325
libx11@2:1.6.7-1+deb10u1
2:1.6.7-1+deb10u3
1
nrrrus/nginx-test:latest5f55cd4ef557
libx11@2:1.7.2-1
2:1.7.2-1+deb11u1
1
octoprint/octoprint:1.4.0106c26efcd8a
libx11@2:1.6.7-1+deb10u1
2:1.6.7-1+deb10u3
1
octoprint/octoprint:1.6.1ea3bffae2470
libx11@2:1.6.7-1+deb10u2
2:1.6.7-1+deb10u3
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libx11@2:1.6.4-3ubuntu0.2
2:1.6.4-3ubuntu0.4+esm1
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libx11@2:1.6.4-3ubuntu0.3
2:1.6.4-3ubuntu0.4+esm1
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libx11@2:1.6.4-3ubuntu0.3
2:1.6.4-3ubuntu0.4+esm1
1
omecproject/onos-progran:1.0.05715e5648aa0
libx11@2:1.6.3-1ubuntu2
2:1.6.3-1ubuntu2.2+esm2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.