CVE-2023-38408
CriticalAdvisory
Published 19 Jul 2023In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.797
- 100th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 179
- of 17,781 indexed, latest versions
- Container images
- 173
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: openssh security update
Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 173 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| opensshdeb | 1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+21 more | 1:6.6p1-2ubuntu2.13+esm1, 1:7.2p2-4ubuntu2.10+esm3, 1:7.6p1-4ubuntu0.7+esm1, 1:7.9p1-10+deb10u3+4 more | 154 |
| opensshapk | 9.0_p1-r1, 9.0_p1-r2, 9.1_p1-r1, 9.1_p1-r2 | 9.0_p1-r4, 9.1_p1-r4 | 10 |
| opensshrpm | 7.4p1-16.el7, 8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8+1 more | 0:7.4p1-23.el7_9, 0:8.0p1-5.el8_2, 0:8.0p1-7.el8_4, 0:8.0p1-19.el8_8 | 9 |
- OSV records
- ALPINE-CVE-2023-38408DEBIAN-CVE-2023-38408RHSA-2023:4381RHSA-2023:4382RHSA-2023:4384RHSA-2023:4419UBUNTU-CVE-2023-38408DLA-3532-1
- Also known as
- USN-6242-1, USN-6242-2
Charts affected
179 by stars
Container images carrying it
173 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 57419b6d3830 | openssh | 9.0_p1-r4 | 1 |
| ghcr.io/ | 24efef013a53 | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | e28e0e7de11b | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | 01563adc95fd | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | 2b92df1143b9 | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | 600221f0f43f | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | a85e03d8bc1d | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | ff2af53897e7 | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| ghcr.io/ | 7217f1a4fa28 | openssh | 1:7.9p1-10+deb10u3 | 1 |
| ghcr.io/ | 73f59c032812 | openssh | 1:7.9p1-10+deb10u3 | 1 |
| public.ecr.aws/ | 573779e57fae | openssh | 1:8.2p1-4ubuntu0.8 | 1 |
| quay.io/ | 5b6701d8fb31 | openssh | 1:8.9p1-3ubuntu0.3 | 1 |
| quay.io/ | cdefc81c6b2e | openssh | 0:8.0p1-7.el8_4 | 1 |
| quay.io/ | d6fd2a9e3273 | openssh | 9.0_p1-r4 | 1 |
| quay.io/ | a3b9a07648b6 | openssh | 0:8.0p1-7.el8_4 | 1 |
| quay.io/ | 7a4b9fedc724 | openssh | 0:8.0p1-5.el8_2 | 1 |
| quay.io/ | 99ccdfd543e1 | openssh | 1:7.9p1-10+deb10u3 | 1 |
| quay.io/ | c241c971aef8 | openssh | 0:8.0p1-19.el8_8 | 1 |
| quay.io/ | defc3263e0e9 | openssh | 9.1_p1-r4 | 1 |
| quay.io/ | c6a934439421 | openssh | 1:7.2p2-4ubuntu2.10+esm3 | 1 |
| quay.io/ | 6ba82beff18e | openssh | 0:8.0p1-19.el8_8 | 1 |
| quay.io/ | e0d9b93dbf2b | openssh | 1:9.2p1-2+deb12u1 | 1 |
| registry.gitlab.com/ | f21f19346b29 | openssh | 1:7.9p1-10+deb10u3 | 1 |