StackRadar

CVE-2023-37920

Critical

Advisory

Published 25 Jul 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
651
deployed by those charts
Fix available
3 of 5
affected packages

Red Hat Bug Fix Advisory: ca-certificates bug fix and enhancement update

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 651 images.

Affected packageAffected versionsFixed inImages
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+19 moreno fix listed83
python-certifideb2018.1.18-2, 2019.11.28-1, 2020.6.20-1, 2022.9.24-1no fix listed57
py3-certifiapk2023.5.7-r02023.7.22-r01
ca-certificatesrpm2018.2.24-6.el8, 2019.2.32-80.0.el8_1, 2020.2.41-80.0.el8_2, 2021.2.50-80.0.el8_4+8 more0:2024.2.69_v8.0.303-80.0.el8_10, 0:2024.2.69_v8.0.303-91.4.el9_4203
certifipypi2017.11.05, 2017.11.5, 2018.1.18, 2018.4.16+21 more2023.7.22427
OSV records
ALPINE-CVE-2023-37920DEBIAN-CVE-2023-37920RHBA-2024:5691RHBA-2024:5736UBUNTU-CVE-2023-37920GHSA-xqr8-7jwr-rhp7
Also known as
PYSEC-2023-135

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,138
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
certifi@2020.12.5
2023.7.22

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2023.7.22

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

11,592
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
certifi@2022.12.7
2023.7.22

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

3,697

Container images carrying it

651 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
aquasec/kube-hunter:1950bf607ce9308
certifi@2018.11.29
2023.7.22
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
certifi@2020.4.5.1
2023.7.22
1
assistiot/fl_repository:latest0fce3ea719a5
certifi@2022.6.15.1
2023.7.22
1
assistiot/fl_training_collector:latest792715dd3084
certifi@2021.10.8
2023.7.22
1
assistiot/identity-manager_kc:latest0df4b4fa899a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
assistiot/open_api_backend:1.1.230812ba93555
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
certifi@2023.5.7
2023.7.22
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
python-certifi@2019.11.28-1
python-pip@20.0.2-5ubuntu1.8
certifi@2019.11.28
no fix listed
no fix listed
2023.7.22
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
certifi@2021.10.8
2023.7.22
1
bbvalabs/sensitive-data:1.0.13ea299ae63c0
certifi@2020.12.5
2023.7.22
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
certifi@2020.4.5.1
2023.7.22
1
beopenit/door-helm:v3.0.1b4d9f9bee224
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
billimek/comcastusage-for-influxdb:latest801bba1228ac
certifi@2018.10.15
2023.7.22
1
billimek/prometheus-uptimerobot-exporter:0.0.1f14ccd7aad0e
certifi@2020.4.5.2
2023.7.22
1
billimek/sb6183-for-influxdb:latestbf8158556035
certifi@2018.4.16
2023.7.22
1
blacktop/httpie:latestfc5e68e2f5ab
certifi@2018.4.16
2023.7.22
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
bootc/puppetboard:1.1.0f1383295e7be
certifi@2019.11.28
2023.7.22
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
bsgrigorov/helm-operator:latest45ab095f09c8
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
buildkite/agent:3.25.0aec38cfaae0e
certifi@2020.6.20
2023.7.22
1
buntha/mlflow:2.1.1154542cc3083
certifi@2022.12.7
2023.7.22
1
calico/node:v3.28.0385bf6391fea
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
calico/node:v3.28.1d8c644a8a3ee
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
camerahub/camerahub:0.36.23a5af37dd6e1b
certifi@2022.12.7
2023.7.22
1
camptocamp/bucket-cloner:latestacfafc308d88
certifi@2021.5.30
2023.7.22
1
camptocamp/ekorre:0.1.035c91d5fda04
certifi@2019.11.28
2023.7.22
1
camptocamp/pghoard:10bff736b15623
certifi@2018.10.15
2023.7.22
1
camptocamp/snow-webhook:latest2924b43dbf40
certifi@2018.8.24
2023.7.22
1
cdignam/kodiak:v0.54.05a6a55b39cee
certifi@2021.5.30
2023.7.22
1
ceph/daemon:latest-nautilus90f30824a96e
certifi@2018.10.15
2023.7.22
1
chaostoolkit/back:latest734f3af86125
certifi@2020.6.20
2023.7.22
1
chaostoolkit/front:latest7f4a7eb9f7df
certifi@2020.11.8
2023.7.22
1
chaostoolkit/middle:latestb95ba4961cfc
certifi@2020.11.8
2023.7.22
1
chetangautamm/repo:sipp.v3e7f7049e1544
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
cheyang/distributed-tf:1.6.046cc34755493
certifi@2018.1.18
2023.7.22
1
chubaofs/cfs-client:3.2.015ff74209ce7
certifi@2021.10.8
2023.7.22
1
chubaofs/cfs-server:3.2.0205030e045f2
certifi@2021.10.8
2023.7.22
1
citizenstig/httpbin:latestb81c818ccb86
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
ckan/ckan-base-datapusher:0.0.2184d11924549f
certifi@2020.12.5
2023.7.22
1
cloudve/janis-terminal:latestaf56e77ca587
python-pip@9.0.1-2.3~ubuntu1.18.04.1
certifi@2020.4.5.2
no fix listed
2023.7.22
1
cloudve/ttyd:latestd79c1c5881c0
certifi@2020.4.5.1
2023.7.22
1
cockroachdb/cockroach:v22.2.91116820f4134
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
cockroachdb/cockroach-operator:v2.1.0983312754620
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
certifi@2020.12.5
2023.7.22
1
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
certifi@2020.4.5.1
2023.7.22
1
coderenvs/coder-service:1.44.61deffc4670e6
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
coderenvs/timescale:1.44.676fd37fe6830
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
codetogether/codetogether:latest4348c8a38752
ca-certificates@2023.2.60_v7.0.306-90.1.el9_2
0:2024.2.69_v8.0.303-91.4.el9_4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.