StackRadar

CVE-2023-38545

Critical

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.785
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+23 more8.4.0-r0198
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+6 more7.81.0-1ubuntu1.14, 7.88.1-10+deb12u468
OSV records
ALPINE-CVE-2023-38545DEBIAN-CVE-2023-38545UBUNTU-CVE-2023-38545
Also known as
USN-6429-1

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.14

Open the chart page →

6,232
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.4.0-r0

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u4

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.4.0-r0

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.4.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.4.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.4.0-r0

Open the chart page →

5,033

Container images carrying it

266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mantlenetworkio/l2geth:v0.4.36bf383d14291
curl@8.2.1-r0
8.4.0-r0
1
metabase/metabase:v0.46.09ebdc664a6b2
curl@7.88.1-r1
8.4.0-r0
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
curl@7.83.1-r4
8.4.0-r0
1
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
curl@7.83.1-r4
8.4.0-r0
1
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
curl@7.83.1-r4
8.4.0-r0
1
moby/buildkit:v0.10.0c2aeafaed434
curl@7.80.0-r0
8.4.0-r0
1
n8nio/n8n:0.212.0a9195bc499a3
curl@7.83.1-r4
8.4.0-r0
1
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.4.0-r0
1
neilpang/acme.sh:3.0.2595809ad43a2
curl@7.80.0-r0
8.4.0-r0
1
netboxcommunity/netbox:v3.2.83d652dca5351
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14
1
oled01/db-backup:0.1.06302fd2b5333
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
openemr/openemr:6.1.089eaa6d9a4e3
curl@7.80.0-r0
8.4.0-r0
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
curl@8.1.2-r0
8.4.0-r0
1
openverso/ueransim:3.2.6733f1232b7d3
curl@7.83.1-r3
8.4.0-r0
1
owntracks/recorder:0.9.370105145f719
curl@7.83.1-r4
8.4.0-r0
1
phntom/chartmuseum:v0.16.053883b65d9b7
curl@8.2.0-r1
8.4.0-r0
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
curl@7.86.0-r1
8.4.0-r0
1
photoprism/photoprism:220629-jammy2954334adbda
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
curl@7.83.1-r1
8.4.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.23.17-nginx-3479ada675515f
curl@8.2.1-r0
8.4.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.22.17-nginx-34b85e437ae261
curl@8.2.1-r0
8.4.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.21.14-nginx-33fa8f5906d36a
curl@8.2.1-r0
8.4.0-r0
1
postgis/postgis:15-3.3-alpine4738bee21eb6
curl@8.2.1-r0
8.4.0-r0
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
curl@7.83.1-r4
8.4.0-r0
1
prefapp/nginx-proxified:latestf4d026fd9a26
curl@7.83.1-r3
8.4.0-r0
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
curl@7.88.1-r1
8.4.0-r0
1
qumine/minecraft-server:v0.1.15c0b650d51132
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
reportportal/migrations:5.7.0da5d8e1395fe
curl@7.80.0-r0
8.4.0-r0
1
reportportal/service-ui:5.7.20a08784eb901
curl@7.83.1-r1
8.4.0-r0
1
santisbon/speedtest:latest8ee3a1697227
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
shyim/shopware:6.4.6.0a951c0e6b836
curl@8.2.1-r0
8.4.0-r0
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
soulou2019/angular-nginx:latesta3970f97c215
curl@7.80.0-r0
8.4.0-r0
1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
curl@7.80.0-r1
8.4.0-r0
1
swaggerapi/swagger-ui:v4.12.00d7088d47928
curl@7.80.0-r1
8.4.0-r0
1
swaggerapi/swagger-ui:v4.15.511b20aebb92c
curl@7.83.1-r3
8.4.0-r0
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
curl@8.2.1-r0
8.4.0-r0
1
swaggerapi/swagger-ui:v4.15.27ff9a86f35ff
curl@7.83.1-r3
8.4.0-r0
1
taemon1337/image-api:0.0.1247bc1dc4f07
curl@7.80.0-r0
8.4.0-r0
1
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
curl@7.80.0-r0
8.4.0-r0
1
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.4.0-r0
1
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.4.0-r0
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.4.0-r0
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.4.0-r0
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
curl@8.3.0-r0
8.4.0-r0
1
thirtythreeforty/neolink:latestf564c4f538de
curl@8.0.1-r2
8.4.0-r0
1
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.