StackRadar

CVE-2023-38545

Critical

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.785
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+23 more8.4.0-r0198
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+6 more7.81.0-1ubuntu1.14, 7.88.1-10+deb12u468
OSV records
ALPINE-CVE-2023-38545DEBIAN-CVE-2023-38545UBUNTU-CVE-2023-38545
Also known as
USN-6429-1

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.14

Open the chart page →

6,232
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.4.0-r0

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u4

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.4.0-r0

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.4.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.4.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.4.0-r0

Open the chart page →

5,033

Container images carrying it

266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcarrarom/landing:0.0.0769d19e441d9
curl@7.83.1-r3
8.4.0-r0
1
glenndehaan/sunflare-tools:latesta5b3f1dd865d
curl@8.2.1-r0
8.4.0-r0
1
grafana/grafana:10.1.11b9ca4bbc4a2
curl@8.2.1-r0
8.4.0-r0
1
grafana/grafana:9.5.239c849cebccc
curl@8.0.1-r0
8.4.0-r0
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
curl@7.83.1-r4
8.4.0-r0
1
groundnuty/k8s-wait-for:v1.684edcf796267
curl@7.80.0-r1
8.4.0-r0
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
curl@7.83.1-r4
8.4.0-r0
1
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u4
1
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.4.0-r0
1
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.4.0-r0
1
hashicorp/waypoint:0.11.397d521a27498
curl@8.1.2-r0
8.4.0-r0
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
1
hazelcast/hazelcast:5.3.18fe26efde8e1
curl@8.2.1-r0
8.4.0-r0
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.14
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
curl@8.3.0-r0
8.4.0-r0
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
curl@8.1.2-r0
8.4.0-r0
1
i4trust/activation-service:2.2.09f3719176893
curl@8.1.2-r0
8.4.0-r0
1
ianw/quickchart:v1.7.1dc49dd460c37
curl@7.80.0-r3
8.4.0-r0
1
ibarreche/cloud-back-ci:lateste16a469c5791
curl@7.80.0-r0
8.4.0-r0
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
invoiceninja/invoiceninja:5.6.241437916dee01
curl@8.1.2-r0
8.4.0-r0
1
iomesh/prepare-csi:v1.0.3-rc0063b18afb6a1
curl@8.1.2-r0
8.4.0-r0
1
iomesh/prepare-csi:v1.0.24206d42b92f1
curl@8.1.2-r0
8.4.0-r0
1
istio/operator:1.18.270f9d1fe5fff
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
1
istio/pilot:1.16.0ac0284d75ec9
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.14
1
istio/pilot:1.15.2db08d6963975
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.14
1
jupyterhub/configurable-http-proxy:4.5.1723028bf9b3c
curl@7.80.0-r0
8.4.0-r0
1
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
curl@8.2.1-r0
8.4.0-r0
1
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
curl@7.83.1-r3
8.4.0-r0
1
kfirfer/king:latestc05d9fc7ae77
curl@8.2.1-r0
8.4.0-r0
1
kfirfer/scripts:0.0.2481e5c4e5d70e
curl@7.80.0-r5
8.4.0-r0
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
curl@7.80.0-r6
8.4.0-r0
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
curl@7.83.1-r2
8.4.0-r0
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
curl@7.83.1-r3
8.4.0-r0
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
curl@8.2.1-r0
8.4.0-r0
1
kyso/jupyter-diff:latest82299a9e5a86
curl@8.2.1-r0
8.4.0-r0
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
curl@7.86.0-r1
8.4.0-r0
1
library/flink:1.14.6-scala_2.122461f02672b3
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.14
1
library/nginx:1.23.2-alpine455c39afebd4
curl@7.83.1-r4
8.4.0-r0
1
library/nginx:1.25.167f9a4f10d14
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
library/php:7-fpm-alpine0aeb129a60da
curl@7.83.1-r4
8.4.0-r0
1
library/sonarqube:10.0.0-communityef9723cf4fe4
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
1
librenms/librenms:22.4.14f1f3d667cc7
curl@7.80.0-r0
8.4.0-r0
1
linuxserver/code-server:4.10.1a5e43a05ae79
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.14
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.4.0-r0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
curl@7.88.1-r1
8.4.0-r0
1
linuxserver/yq:3.2.26f5b9586a93e
curl@8.2.1-r0
8.4.0-r0
1
liukunup/jmeter:5.59c079617a81b
curl@7.83.1-r3
8.4.0-r0
1
livekit/ingress:v1.2.21ab01641b366
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.