StackRadar

CVE-2023-3576

Medium

Advisory

Published 4 Oct 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
105
of 17,781 indexed, latest versions
Container images
111
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 105 of 17,781 indexed charts deploy, on 111 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+20 more4.0.3-7ubuntu0.11+esm11, 4.0.6-1ubuntu0.8+esm14, 4.0.9-5ubuntu0.10+esm4, 4.1.0+git191117-2ubuntu0.20.04.11+2 more111
OSV records
DEBIAN-CVE-2023-3576UBUNTU-CVE-2023-3576
Also known as
USN-6512-1

Charts affected

105 by stars
ChartLatestAffected imagesRadar Score
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-3576.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.11

Open the chart page →

30,687
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-3576.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
tiff@4.5.0-6
4.5.0-6+deb12u1

Open the chart page →

20,223
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-3576.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
tiff@4.5.0-6
4.5.0-6+deb12u1

Open the chart page →

6,297
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2023-3576.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
tiff@4.3.0-6
4.3.0-6ubuntu0.7
xeladock/nginx2:latestc259a67b1dff
tiff@4.3.0-6
4.3.0-6ubuntu0.7

Open the chart page →

17,461
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-3576.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tiff@4.5.0-6
4.5.0-6+deb12u1

Open the chart page →

14,358

Container images carrying it

111 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.11
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm4
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.11
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
tiff@4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.11
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
tiff@4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.11
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
tiff@4.5.0-6
4.5.0-6+deb12u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
tiff@4.5.0-6
4.5.0-6+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
tiff@4.5.0-6
4.5.0-6+deb12u1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.11
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tiff@4.0.6-1ubuntu0.6
4.0.6-1ubuntu0.8+esm14
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tiff@4.5.0-6
4.5.0-6+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.