StackRadar

CVE-2023-3446

Medium

Advisory

Published 19 Jul 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.065
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,202
of 17,787 indexed, latest versions
Container images
1,218
deployed by those charts
Fix available
4 of 5
affected packages

libopenssl-1_1-devel-1.1.1u-5.1 on GA media

Carried by container images the latest versions of 1,202 of 17,787 indexed charts deploy, on 1,218 images.

Affected packageAffected versionsFixed inImages
opensslapk1.1.1l-r7, 1.1.1l-r8, 1.1.1m-r1, 1.1.1n-r0+20 more1.1.1u-r2, 3.0.9-r3, 3.1.1-r3627
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+60 more1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm10, 1.1.1-1ubuntu2.1~18.04.23+esm3, 1.1.1f-1ubuntu2.20+4 more580
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm115
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
openssl-1_1rpm1.1.0i-14.6.1, 1.1.0i-lp151.8.3.11.1.0i-150100.14.59.1, 1.1.1u-5.19
OSV records
ALPINE-CVE-2023-3446DEBIAN-CVE-2023-3446UBUNTU-CVE-2023-3446openSUSE-SU-2024:13064-1SUSE-SU-2023:2961-1
Also known as
USN-6435-1, USN-6435-2, USN-6450-1, USN-6709-1, USN-7018-1

Charts affected

1,202 by stars
ChartLatestAffected imagesRadar Score
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-3446.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
openssl@1.1.1l-r7
1.1.1u-r2

Open the chart page →

3,118
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2023-3446.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm3
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.20

Open the chart page →

9,250

Container images carrying it

1,218 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/ui:2.16.2af9c9349708f
openssl@3.1.1-r1
3.1.1-r3
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nodejs@16.14.2-deb-1nodesource1
openssl@3.0.2-0ubuntu1.9
no fix listed
3.0.2-0ubuntu1.12
2
wurstmeister/zookeeper:latest7a7fd44a7210
openssl@1.0.1f-1ubuntu2.5
1.0.1f-1ubuntu2.27+esm10
2
xelalex/dregsy:0.4.3574054e1c417
openssl@1.1.1o-r0
1.1.1u-r2
2
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
openssl@1.0.2g-1ubuntu4.8
1.0.2g-1ubuntu4.20+esm10
2
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
openssl@3.0.8-r3
3.0.9-r3
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.12
2
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
openssl@3.0.7-r0
3.0.9-r3
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.12
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.20
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.20
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.20
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm3
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
openssl@1.1.1l-r7
1.1.1u-r2
2
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
openssl@1.1.1q-r0
1.1.1u-r2
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm3
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm3
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.12
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
openssl@3.0.8-r0
3.0.9-r3
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.20
2
quay.io/frrouting/frr:8.4.254f9a7b9e543
openssl@1.1.1q-r0
1.1.1u-r2
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
openssl@1.1.1q-r0
1.1.1u-r2
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
openssl@1.1.1n-r0
1.1.1u-r2
2
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
openssl@1.1.1n-r0
1.1.1u-r2
2
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
openssl@1.1.1n-r0
1.1.1u-r2
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
openssl@1.1.1n-r0
1.1.1u-r2
2
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
openssl@1.1.1n-r0
1.1.1u-r2
2
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
openssl@1.1.1o-r0
1.1.1u-r2
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
openssl@3.1.0-r4
3.1.1-r3
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
openssl@1.1.1n-r0
1.1.1u-r2
2
0hlov3/semaphore:v1.0.050f874ec096b
openssl@3.0.8-r0
3.0.9-r3
1
300481/shield:0.3.18e11c521c2d8
openssl@1.1.1q-r0
1.1.1u-r2
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
openssl@3.0.9-1
3.0.10-1~deb12u1
1
5200710/hadoop:3.2.3-java8092d3088a5fb
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.fips.20
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm3
1
abdullahkhabir/radio:latest56526d0cc929
openssl@3.0.7-r2
3.0.9-r3
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.20
1
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
openssl@1.1.1q-r0
1.1.1u-r2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.20
1
akaunting/akaunting:3.0.1552811b36ec3a
openssl@3.0.9-1
3.0.10-1~deb12u1
1
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
openssl@1.1.1q-r0
1.1.1u-r2
1
alaaamin/reload-count-tornado-py-app:v1.0.1alpine46da5844794e
openssl@1.1.1q-r0
1.1.1u-r2
1
alexeyr7/sf-test-app:latestdf0b41fdbd53
openssl@1.1.1o-r0
1.1.1u-r2
1
alexvm6/generator:latestfb99ee4f760a
openssl@3.1.0-r4
3.1.1-r3
1
alexvm6/pythonalex:latest89a05786879c
openssl@3.1.0-r4
3.1.1-r3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
openssl@1.1.1-1ubuntu2.1~18.04.19
openssl1.0@1.0.2n-1ubuntu5.10
1.1.1-1ubuntu2.1~18.04.23+esm3
1.0.2n-1ubuntu5.13+esm1
1
alpine/git:2.36.366b210a97bc0
openssl@1.1.1s-r0
1.1.1u-r2
1
alpine/k8s:1.22.600ac10bcb759
openssl@1.1.1n-r0
1.1.1u-r2
1
alpine/k8s:1.27.321b24e6bf801
openssl@3.1.1-r1
3.1.1-r3
1
amagdi888/my-repo:hello-appd8a10fc8faf6
openssl@1.1.1q-r0
1.1.1u-r2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.