CVE-2023-3247
MediumAdvisory
Published 13 Jun 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.3
- base score, highest
- EPSS
- 0.007
- 52nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 19
- of 17,781 indexed, latest versions
- Container images
- 13
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
php7.3 - security update
Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 13 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| php7.4deb | 7.4.3-4ubuntu2.6, 7.4.3-4ubuntu2.12, 7.4.3-4ubuntu2.13, 7.4.3-4ubuntu2.15+4 more | 7.4.3-4ubuntu2.19, 7.4.33-1+deb11u4 | 8 |
| php8.1deb | 8.1.2-1ubuntu2.3 | 8.1.2-1ubuntu2.13 | 1 |
| php7.3deb | 7.3.4-2, 7.3.11-1~deb10u1, 7.3.14-1~deb10u1, 7.3.31-1~deb10u1 | 7.3.31-1~deb10u4 | 4 |
- OSV records
- UBUNTU-CVE-2023-3247DLA-3458-1DSA-5424-1
- Also known as
- USN-6199-1
Charts affected
19 by stars
Container images carrying it
13 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| osixia/ | d112b82be133 | php7.3 | 7.3.31-1~deb10u4 | 5 |
| ldapaccountmanager/ | d46cf25d1dda | php7.4 | 7.4.33-1+deb11u4 | 2 |
| passbolt/ | 655547e17263 | php7.4 | 7.4.33-1+deb11u4 | 2 |
| eaudeweb/ | b8ad9b7e19bb | php7.3 | 7.3.31-1~deb10u4 | 1 |
| fossology/ | 8bd1f22ba7bb | php7.3 | 7.3.31-1~deb10u4 | 1 |
| kfirfer/ | 2efb4a5d74a3 | php7.4 | 7.4.3-4ubuntu2.19 | 1 |
| ldapaccountmanager/ | 95533a96a4c1 | php7.3 | 7.3.31-1~deb10u4 | 1 |
| mediagis/ | c15e941485ef | php7.4 | 7.4.3-4ubuntu2.19 | 1 |
| passbolt/ | ec046e112d5c | php7.4 | 7.4.33-1+deb11u4 | 1 |
| pihole/ | b83258064f54 | php7.4 | 7.4.33-1+deb11u4 | 1 |
| snipe/ | 55fb7636a98c | php7.4 | 7.4.3-4ubuntu2.19 | 1 |
| zabbix/ | 01de79c31391 | php7.4 | 7.4.3-4ubuntu2.19 | 1 |
| zabbix/ | 99e9a090b516 | php8.1 | 8.1.2-1ubuntu2.13 | 1 |