StackRadar

CVE-2023-37920

Critical

Advisory

Published 25 Jul 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
651
deployed by those charts
Fix available
3 of 5
affected packages

Red Hat Bug Fix Advisory: ca-certificates bug fix and enhancement update

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 651 images.

Affected packageAffected versionsFixed inImages
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+19 moreno fix listed83
python-certifideb2018.1.18-2, 2019.11.28-1, 2020.6.20-1, 2022.9.24-1no fix listed57
py3-certifiapk2023.5.7-r02023.7.22-r01
ca-certificatesrpm2018.2.24-6.el8, 2019.2.32-80.0.el8_1, 2020.2.41-80.0.el8_2, 2021.2.50-80.0.el8_4+8 more0:2024.2.69_v8.0.303-80.0.el8_10, 0:2024.2.69_v8.0.303-91.4.el9_4203
certifipypi2017.11.05, 2017.11.5, 2018.1.18, 2018.4.16+21 more2023.7.22427
OSV records
ALPINE-CVE-2023-37920DEBIAN-CVE-2023-37920RHBA-2024:5691RHBA-2024:5736UBUNTU-CVE-2023-37920GHSA-xqr8-7jwr-rhp7
Also known as
PYSEC-2023-135

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,138
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
certifi@2020.12.5
2023.7.22

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2023.7.22

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

11,592
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
certifi@2022.12.7
2023.7.22

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

3,697

Container images carrying it

651 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
voltha/voltha-tester:1.7.0655c3048a602
python-pip@8.1.1-2ubuntu0.4
certifi@2019.6.16
no fix listed
2023.7.22
1
voltha/voltha-voltha:1.6.0ff596b62de59
python-pip@8.1.1-2ubuntu0.4
certifi@2018.10.15
no fix listed
2023.7.22
1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
certifi@2018.8.24
2023.7.22
1
wazuh/wazuh-manager:4.4.121994f40e0da
certifi@2022.12.7
2023.7.22
1
weblate/weblate:3.11.3-182848df56ecd
certifi@2019.11.28
2023.7.22
1
wiremind/pghoard:12-2019-11-264dea42c8166c
certifi@2019.9.11
2023.7.22
1
witcherek7/pav:0.0.342a744f29ac0
certifi@2022.12.7
2023.7.22
1
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed
1
zohardocker12/weather_app_flask:latestb86d60dbb68d
certifi@2021.10.8
2023.7.22
1
gcr.io/google-samples/microservices-demo/loadgenerator:v0.2.3360130ab5850
certifi@2020.12.5
2023.7.22
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
certifi@2020.12.5
2023.7.22
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
certifi@2021.10.8
2023.7.22
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
python-certifi@2022.9.24-1
certifi@2022.9.24
no fix listed
2023.7.22
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
certifi@2020.12.5
2023.7.22
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
certifi@2020.12.5
2023.7.22
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
certifi@2022.12.7
2023.7.22
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
certifi@2022.9.24
2023.7.22
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/cunningpike/fediblockhole:0.4.22abc5f0350dc
certifi@2022.12.7
2023.7.22
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
certifi@2021.10.8
2023.7.22
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
certifi@2021.10.8
2023.7.22
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
ca-certificates@2022.2.54-90.2.el9_0
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
certifi@2020.6.20
2023.7.22
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.