StackRadar

CVE-2023-37920

Critical

Advisory

Published 25 Jul 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
651
deployed by those charts
Fix available
3 of 5
affected packages

Red Hat Bug Fix Advisory: ca-certificates bug fix and enhancement update

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 651 images.

Affected packageAffected versionsFixed inImages
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+19 moreno fix listed83
python-certifideb2018.1.18-2, 2019.11.28-1, 2020.6.20-1, 2022.9.24-1no fix listed57
py3-certifiapk2023.5.7-r02023.7.22-r01
ca-certificatesrpm2018.2.24-6.el8, 2019.2.32-80.0.el8_1, 2020.2.41-80.0.el8_2, 2021.2.50-80.0.el8_4+8 more0:2024.2.69_v8.0.303-80.0.el8_10, 0:2024.2.69_v8.0.303-91.4.el9_4203
certifipypi2017.11.05, 2017.11.5, 2018.1.18, 2018.4.16+21 more2023.7.22427
OSV records
ALPINE-CVE-2023-37920DEBIAN-CVE-2023-37920RHBA-2024:5691RHBA-2024:5736UBUNTU-CVE-2023-37920GHSA-xqr8-7jwr-rhp7
Also known as
PYSEC-2023-135

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,138
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
certifi@2020.12.5
2023.7.22

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2023.7.22

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

11,592
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
certifi@2022.12.7
2023.7.22

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

3,697

Container images carrying it

651 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
certifi@2021.10.8
2023.7.22
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
ca-certificates@2023.2.60_v7.0.306-90.1.el9_2
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
ca-certificates@2019.2.32-80.0.el8_1
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
certifi@2022.6.15
2023.7.22
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
certifi@2021.5.30
2023.7.22
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
certifi@2021.10.8
2023.7.22
1
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
certifi@2022.9.24
2023.7.22
1
ghcr.io/linuxserver/tvheadend:version-eb59284b66c4c9e18e40
certifi@2020.4.5.1
2023.7.22
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
certifi@2022.6.15
2023.7.22
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
certifi@2022.12.7
2023.7.22
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
certifi@2022.12.7
2023.7.22
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
certifi@2022.12.7
2023.7.22
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
certifi@2022.12.7
2023.7.22
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
certifi@2023.5.7
2023.7.22
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
certifi@2023.5.7
2023.7.22
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
certifi@2022.6.15
2023.7.22
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
ca-certificates@2023.2.60_v7.0.306-90.1.el9_2
0:2024.2.69_v8.0.303-91.4.el9_4
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
certifi@2023.5.7
2023.7.22
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
certifi@2023.5.7
2023.7.22
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
certifi@2023.5.7
2023.7.22
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python-pip@20.0.2-5ubuntu1.6
certifi@2022.9.24
no fix listed
2023.7.22
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python-pip@20.0.2-5ubuntu1.6
certifi@2022.9.24
no fix listed
2023.7.22
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
certifi@2023.5.7
2023.7.22
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
certifi@2018.10.15
2023.7.22
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
certifi@2022.5.18.1
2023.7.22
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
certifi@2021.5.30
2023.7.22
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.