StackRadar

CVE-2023-37920

Critical

Advisory

Published 25 Jul 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
607
of 17,787 indexed, latest versions
Container images
648
deployed by those charts
Fix available
3 of 5
affected packages

Red Hat Bug Fix Advisory: ca-certificates bug fix and enhancement update

Carried by container images the latest versions of 607 of 17,787 indexed charts deploy, on 648 images.

Affected packageAffected versionsFixed inImages
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+19 moreno fix listed83
python-certifideb2018.1.18-2, 2019.11.28-1, 2020.6.20-1, 2022.9.24-1no fix listed57
py3-certifiapk2023.5.7-r02023.7.22-r01
ca-certificatesrpm2018.2.24-6.el8, 2019.2.32-80.0.el8_1, 2020.2.41-80.0.el8_2, 2021.2.50-80.0.el8_4+8 more0:2024.2.69_v8.0.303-80.0.el8_10, 0:2024.2.69_v8.0.303-91.4.el9_4203
certifipypi2017.11.05, 2017.11.5, 2018.1.18, 2018.4.16+21 more2023.7.22424
OSV records
ALPINE-CVE-2023-37920DEBIAN-CVE-2023-37920RHBA-2024:5691RHBA-2024:5736UBUNTU-CVE-2023-37920GHSA-xqr8-7jwr-rhp7
Also known as
PYSEC-2023-135

Charts affected

607 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
certifi@2020.12.5
2023.7.22

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2023.7.22

Open the chart page →

2,643
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
certifi@2022.12.7
2023.7.22

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-37920.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10

Open the chart page →

3,697

Container images carrying it

648 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
certifi@2019.3.9
no fix listed
2023.7.22
11
codeurjc/weatherservice:v1.0b9e2f7234349
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
10
codeurjc/server:v1.0310bea5b1ee7
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
8
oomk8s/readiness-check:2.0.07daa08b81954
python-pip@8.1.1-2ubuntu0.4
certifi@2018.1.18
no fix listed
2023.7.22
6
mastercloudapps/server:v2.23f3d24dfe2686
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
4
mastercloudapps/weatherservice:v1.23de859d29c116
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
4
quay.io/strimzi/operator:0.37.052f376e64b9b
ca-certificates@2022.2.54-80.2.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
4
cloudve/cloudlaunch-server:latest4a3d7fae90bb
python-pip@20.0.2-5ubuntu1.6
certifi@2021.10.8
no fix listed
2023.7.22
3
dpage/pgadmin4:6.12781369df9994
certifi@2020.12.5
2023.7.22
3
kiwigrid/k8s-sidecar:0.1.193170069ff0976
certifi@2020.6.20
2023.7.22
3
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
certifi@2020.4.5.1
2023.7.22
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
3
mysql/mysql-server:latestd6c8301b7834
certifi@2022.9.24
2023.7.22
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
ca-certificates@2020.2.41-80.0.el8_2
0:2024.2.69_v8.0.303-80.0.el8_10
3
quay.io/devtron/clair:4.3.675fb847ac045
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
3
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
certifi@2021.5.30
2023.7.22
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
ca-certificates@2023.2.60_v7.0.306-80.0.el8_6
0:2024.2.69_v8.0.303-80.0.el8_10
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
3
amancevice/superset:0.35.212a0a9e66550
certifi@2019.11.28
2023.7.22
2
aquasec/kube-hunter:0.6.8e64fe49f059f
certifi@2021.10.8
2023.7.22
2
blakeblackshear/frigate:0.11.18330b0a265b8
certifi@2022.9.24
2023.7.22
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
ca-certificates@2022.2.54-80.2.el8_6
certifi@2023.5.7
0:2024.2.69_v8.0.303-80.0.el8_10
2023.7.22
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
ca-certificates@2022.2.54-80.2.el8_6
certifi@2023.5.7
0:2024.2.69_v8.0.303-80.0.el8_10
2023.7.22
2
cs3org/wopiserver:v9.4.202a9e78757b4
certifi@2022.12.7
2023.7.22
2
datawire/aes:1.14.48588eafe6862
certifi@2020.6.20
2023.7.22
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
certifi@2023.5.7
2023.7.22
2
hjacobs/kube-ops-view:20.4.058221b57d4d2
certifi@2020.4.5.1
2023.7.22
2
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
certifi@2019.3.9
2023.7.22
2
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
certifi@2019.3.9
2023.7.22
2
kiwigrid/k8s-sidecar:1.24.44138bea678f0
certifi@2023.5.7
2023.7.22
2
kiwigrid/k8s-sidecar:1.24.35af76eebbba7
certifi@2023.5.7
2023.7.22
2
larribas/mlflow:1.9.105ccb0b46bfb
certifi@2020.6.20
2023.7.22
2
lncm/specter-desktop:v1.10.536eaa06f99f4
certifi@2021.10.8
2023.7.22
2
louislam/uptime-kuma:2.5.4917318f9d7be
python-certifi@2022.9.24-1
certifi@2022.9.24
no fix listed
2023.7.22
2
louislam/uptime-kuma:2.3.29aeb4e51d038
certifi@2022.9.24
python-certifi@2022.9.24-1
2023.7.22
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
python-certifi@2022.9.24-1
certifi@2022.9.24
no fix listed
2023.7.22
2
minio/operator:v4.3.754393e03f3b2
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
2
neuvector/manager:3.2.1f1b7d666eae0
certifi@2019.11.28
2023.7.22
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2023.7.22
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
certifi@2019.6.16
2023.7.22
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
python-pip@8.1.1-2ubuntu0.4
certifi@2018.8.24
no fix listed
2023.7.22
2
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
certifi@2020.12.5
2023.7.22
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
python-pip@20.0.2-5ubuntu1.6
no fix listed
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
ca-certificates@2021.2.50-80.0.el8_4
0:2024.2.69_v8.0.303-80.0.el8_10
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
python-pip@22.0.2+dfsg-1ubuntu0.2
no fix listed
2
weblate/weblate:4.2.2-169c160d37a3c
certifi@2020.6.20
2023.7.22
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
certifi@2023.5.7
2023.7.22
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2023.7.22
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
ca-certificates@2023.2.60_v7.0.306-80.0.el8_8
0:2024.2.69_v8.0.303-80.0.el8_10
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.