StackRadar

CVE-2023-38545

Critical

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.785
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+23 more8.4.0-r0198
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+6 more7.81.0-1ubuntu1.14, 7.88.1-10+deb12u468
OSV records
ALPINE-CVE-2023-38545DEBIAN-CVE-2023-38545UBUNTU-CVE-2023-38545
Also known as
USN-6429-1

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.14

Open the chart page →

6,232
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.4.0-r0

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u4

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.4.0-r0

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.4.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.4.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.4.0-r0

Open the chart page →

5,033

Container images carrying it

266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/git:2.36.366b210a97bc0
curl@7.83.1-r4
8.4.0-r0
1
alpine/k8s:1.22.600ac10bcb759
curl@7.80.0-r0
8.4.0-r0
1
alpine/k8s:1.27.321b24e6bf801
curl@8.1.2-r0
8.4.0-r0
1
alpine/k8s:1.28.2fc059f056ad0
curl@8.3.0-r0
8.4.0-r0
1
anonaddy/anonaddy:0.12.3957a95565166
curl@7.83.1-r2
8.4.0-r0
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14
1
apache/skywalking-oap-server:9.2.0133d35d2c263
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14
1
apache/skywalking-ui:9.2.0295f1dc87d98
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14
1
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.4.0-r0
1
aquasec/trivy:0.43.1944a04445179
curl@8.1.2-r0
8.4.0-r0
1
aquasec/trivy:0.32.0973d0df16189
curl@7.83.1-r3
8.4.0-r0
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
curl@7.83.1-r3
8.4.0-r0
1
assistiot/location_processing:lateste9bae124095f
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
assistiot/open_api_kong:1.0.03fe850384689
curl@7.83.1-r4
8.4.0-r0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
curl@7.83.1-r3
8.4.0-r0
1
atlassian/confluence-server:7.10.03b9222ab32ef
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
avinash263/pyredis263:latestaa2b8727f1a6
curl@7.88.1-10
7.88.1-10+deb12u4
1
bicarus/wg-access-server:v0.8.206cab48e9334
curl@7.83.1-r3
8.4.0-r0
1
blockscout/blockscout:5.1.5c365a8f2dc12
curl@7.83.1-r5
8.4.0-r0
1
casbin/casdoor:v1.224.066f836ef778b
curl@7.87.0-r1
8.4.0-r0
1
chaosnative/cle-frontend:2.7.007b82a82a702
curl@7.80.0-r0
8.4.0-r0
1
charmcli/soft-serve:v0.4.039523c1a6ba8
curl@7.83.1-r2
8.4.0-r0
1
clastix/kubectl:v1.2187fabaccb3a6
curl@7.80.0-r0
8.4.0-r0
1
clastix/kubectl:v1.22d0376d87ac6b
curl@7.80.0-r0
8.4.0-r0
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
curl@8.1.2-r0
8.4.0-r0
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
curl@7.87.0-r0
8.4.0-r0
1
devopstales/trivy-operator:2.575136aa7a26e
curl@7.87.0-r1
8.4.0-r0
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
curl@7.80.0-r3
8.4.0-r0
1
dnsforge/xteve:latest4d9a685c8c28
curl@7.87.0-r1
8.4.0-r0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
curl@7.88.1-r0
8.4.0-r0
1
duck1123/cert-downloader:latest0e29f19fa67c
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14
1
duck1123/lnd-fileserver:latest9d6fb247b714
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
curl@7.80.0-r2
8.4.0-r0
1
emqx/emqx:4.4.41d36535ba9de
curl@7.80.0-r1
8.4.0-r0
1
emqx/emqx:4.4.1971db5ed95db3
curl@8.1.2-r0
8.4.0-r0
1
ethereumoptimism/l2geth:0.5.315577036dc36d
curl@7.80.0-r5
8.4.0-r0
1
factly/mande-studio:0.34.19db4bee30e63
curl@8.2.1-r0
8.4.0-r0
1
fedodo/fedodo.ui.home:3c69413c4d690
curl@8.1.2-r0
8.4.0-r0
1
fedodo/fedodo.ui.micro:12b2b540081c21
curl@8.1.2-r0
8.4.0-r0
1
felipecs8/qrcode-generator:v1d5f4f17cb066
curl@7.87.0-r1
8.4.0-r0
1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
curl@8.1.2-r0
8.4.0-r0
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
curl@7.83.1-r3
8.4.0-r0
1
flomesh/pipy-repo:0.90.3-3874975c50e3d9
curl@8.3.0-r0
8.4.0-r0
1
folioci/mod-aes:latest6d67e9564270
curl@7.83.1-r2
8.4.0-r0
1
folioci/mod-codex-ekb:latest235a3fa4adc9
curl@7.83.1-r3
8.4.0-r0
1
folioci/mod-codex-inventory:latest6d53ed758fd1
curl@7.83.1-r3
8.4.0-r0
1
folioci/mod-codex-mux:latestd4138abfd30d
curl@7.83.1-r3
8.4.0-r0
1
folioci/mod-data-import-converter-storage:latest3028f333778f
curl@7.87.0-r0
8.4.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.