StackRadar

CVE-2023-37920

Critical

Advisory

Published 25 Jul 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
607
of 17,787 indexed, latest versions
Container images
648
deployed by those charts
Fix available
3 of 5
affected packages

Red Hat Bug Fix Advisory: ca-certificates bug fix and enhancement update

Carried by container images the latest versions of 607 of 17,787 indexed charts deploy, on 648 images.

Affected packageAffected versionsFixed inImages
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+19 moreno fix listed83
python-certifideb2018.1.18-2, 2019.11.28-1, 2020.6.20-1, 2022.9.24-1no fix listed57
py3-certifiapk2023.5.7-r02023.7.22-r01
ca-certificatesrpm2018.2.24-6.el8, 2019.2.32-80.0.el8_1, 2020.2.41-80.0.el8_2, 2021.2.50-80.0.el8_4+8 more0:2024.2.69_v8.0.303-80.0.el8_10, 0:2024.2.69_v8.0.303-91.4.el9_4203
certifipypi2017.11.05, 2017.11.5, 2018.1.18, 2018.4.16+21 more2023.7.22424
OSV records
ALPINE-CVE-2023-37920DEBIAN-CVE-2023-37920RHBA-2024:5691RHBA-2024:5736UBUNTU-CVE-2023-37920GHSA-xqr8-7jwr-rhp7
Also known as
PYSEC-2023-135

Charts affected

607 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
certifi@2020.12.5
2023.7.22

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2023.7.22

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
certifi@2022.12.7
2023.7.22

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

3,697

Container images carrying it

648 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
certifi@2022.12.7
2023.7.22
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
certifi@2020.12.5
2023.7.22
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python-certifi@2019.11.28-1
python-pip@20.0.2-5ubuntu1.11
certifi@2019.11.28
no fix listed
no fix listed
2023.7.22
1
fiware/mintaka:0.7.092a3c5cf43c0
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
fiware/mintaka:latestefc6793388cc
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
1
flag5/clustersecret:0.0.94ad5748bfcc6
certifi@2021.10.8
2023.7.22
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
certifi@2020.11.8
2023.7.22
1
flyway/flyway:9.1545b5d7cdc75a
python-pip@20.0.2-5ubuntu1.8
no fix listed
1
fossology/fossology:4.2.18bd1f22ba7bb
certifi@2022.9.24
2023.7.22
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
python-pip@9.0.1-2.3~ubuntu1.18.04.6
certifi@2022.12.7
no fix listed
2023.7.22
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python-pip@9.0.1-2.3~ubuntu1.18.04.5
certifi@2022.6.15
no fix listed
2023.7.22
1
galaxy/cloudman-server:lateste5c265fe9fcd
python-pip@20.0.2-5ubuntu1.6
certifi@2022.9.14
no fix listed
2023.7.22
1
galaxy/galaxy-init:v18.010267bad550e6
python-pip@1.5.4-1ubuntu4
certifi@2017.11.05
no fix listed
2023.7.22
1
galaxy/galaxy-stable:v18.018e577a626dfd
python-pip@1.5.4-1ubuntu4
certifi@2018.4.16
no fix listed
2023.7.22
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
python-pip@9.0.1-2.3~ubuntu1.18.04.2
certifi@2020.6.20
no fix listed
2023.7.22
1
gethue/hue:4.11.011b649636e68
python-pip@20.0.2-5ubuntu1.6
certifi@2022.12.7
no fix listed
2023.7.22
1
gethue/hue:4.10.05702b2c37ff9
python-pip@9.0.1-2.3~ubuntu1.18.04.5
certifi@2021.5.30
no fix listed
2023.7.22
1
gethue/hue:latest7d5c1b9f8a79
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
certifi@2018.11.29
2023.7.22
1
gluufederation/opendj:4.3.0_011a1128b28b95
certifi@2020.12.5
2023.7.22
1
gmaas2/github-api:latest148fc2d9afe9
certifi@2022.12.7
2023.7.22
1
gmelillo/registry:0.1.8c599d608a2f7
certifi@2020.12.5
2023.7.22
1
goofball222/pritunl:1.30.3070.5943c0743701d4
certifi@2021.10.8
2023.7.22
1
goofball222/pritunl:1.32.3602.807bf26032dfce
certifi@2022.12.7
2023.7.22
1
greenbirdit/locust:0.9.0e99d53bdc944
certifi@2018.11.29
2023.7.22
1
gristlabs/grist:0.7.96e71b1914a7e
certifi@2021.10.8
2023.7.22
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
gurolakman/ussigw-core:1.0.48739565c3ea2
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
1
ha33ona/python:test6affdfc644d0
certifi@2022.12.7
2023.7.22
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
certifi@2019.6.16
2023.7.22
1
haveagitgat/tdarr:2.00.181256348872ce
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
python-certifi@2019.11.28-1
certifi@2019.11.28
no fix listed
2023.7.22
1
hazelcast/management-center:5.3.2f9d34300d330
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
1
hcguersoy/cleanreg:v0.8.063b76fdcfbe1
certifi@2021.10.8
2023.7.22
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
certifi@2022.12.7
2023.7.22
1
helga09/my_sql_shoes:v1.1.1a03657d97897
certifi@2022.9.24
2023.7.22
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
hhyo/archery:v1.9.11aa41843419e
certifi@2022.9.24
2023.7.22
1
hiboxsystems/marge-bot:0.11.07235809b43b3
certifi@2020.12.5
2023.7.22
1
hjacobs/kube-downscaler:23.2.05d328c003efe
certifi@2022.9.14
2023.7.22
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
certifi@2023.5.7
2023.7.22
1
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
certifi@2023.5.7
2023.7.22
1
hjacobs/kube-resource-report:21.2.145f93491c434
certifi@2020.12.5
2023.7.22
1
hjacobs/kube-resource-report:22.11.0c173cd02f5af
certifi@2022.9.24
2023.7.22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.