StackRadar

CVE-2023-38545

Critical

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.785
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+23 more8.4.0-r0198
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+6 more7.81.0-1ubuntu1.14, 7.88.1-10+deb12u468
OSV records
ALPINE-CVE-2023-38545DEBIAN-CVE-2023-38545UBUNTU-CVE-2023-38545
Also known as
USN-6429-1

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14

Open the chart page →

3,729
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14

Open the chart page →

5,604
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
curl@7.87.0-r1
8.4.0-r0

Open the chart page →

3,649
cluster-componentkubebb0.2.21 of 4See more

cluster-component kubebb 0.2.2

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
curl@7.83.1-r2
8.4.0-r0

Open the chart page →

8,160
ingress-nginxkubebb4.7.01 of 2See more

ingress-nginx kubebb 4.7.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.4.0-r0

Open the chart page →

3,099
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
curl@8.2.1-r0
8.4.0-r0

Open the chart page →

3,561
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
curl@8.2.1-r0
8.4.0-r0

Open the chart page →

7,356
kusk-gateway-dashboardkubeshop0.1.191 of 1See more

kusk-gateway-dashboard kubeshop 0.1.19

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
curl@7.83.1-r3
8.4.0-r0

Open the chart page →

1,216
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
grafana/grafana:9.5.239c849cebccc
curl@8.0.1-r0
8.4.0-r0

Open the chart page →

18,316
iomeshkubesphere-stable1.1.02 of 25See more

iomesh kubesphere-stable 1.1.0

2 of the 25 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
iomesh/prepare-csi:v1.0.24206d42b92f1
curl@8.1.2-r0
8.4.0-r0
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

48,665
IOMeshkubesphere-stable1.2.02 of 25See more

IOMesh kubesphere-stable 1.2.0

2 of the 25 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
iomesh/prepare-csi:v1.0.3-rc0063b18afb6a1
curl@8.1.2-r0
8.4.0-r0
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

46,341
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
curl@8.2.1-r0
8.4.0-r0

Open the chart page →

7,802
jupyter-diffkyso1.0.01 of 1See more

jupyter-diff kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
kyso/jupyter-diff:latest82299a9e5a86
curl@8.2.1-r0
8.4.0-r0

Open the chart page →

1,172
laravel-chartlaravel-application0.2.01 of 1See more

laravel-chart laravel-application 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ibarreche/cloud-back-ci:lateste16a469c5791
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

1,835
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
curl@7.83.1-r3
8.4.0-r0

Open the chart page →

4,271
owntracks-reporterleprechaun-charts0.2.131 of 1See more

owntracks-reporter leprechaun-charts 0.2.13

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
owntracks/recorder:0.9.370105145f719
curl@7.83.1-r4
8.4.0-r0

Open the chart page →

875
qbittorrentlib42Verified publisher1.0.01 of 1See more

qbittorrent lib42 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
curl@8.0.1-r2
8.4.0-r0

Open the chart page →

2,167
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14

Open the chart page →

10,716
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.101 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
curl@7.83.1-r5
8.4.0-r0

Open the chart page →

5,768
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.1723028bf9b3c
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

17,779
xteveluiscajl0.1.61 of 1See more

xteve luiscajl 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
dnsforge/xteve:latest4d9a685c8c28
curl@7.87.0-r1
8.4.0-r0

Open the chart page →

4,314
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
curl@8.2.1-r0
8.4.0-r0

Open the chart page →

5,940
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

7,327
ingressmedia-streaming-meshVerified publisher0.1.81 of 2See more

ingress media-streaming-mesh 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
curl@7.88.1-r1
8.4.0-r0

Open the chart page →

3,301
MINTmint8.0.24 of 15See more

MINT mint 8.0.2

4 of the 15 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
curl@7.83.1-r4
8.4.0-r0
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
curl@7.83.1-r4
8.4.0-r0
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
curl@7.83.1-r4
8.4.0-r0
postgis/postgis:10-3.2-alpine7e3e68a36d53
curl@7.83.1-r4
8.4.0-r0

Open the chart page →

43,341
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4

Open the chart page →

6,853
acmemosquitto-helm-chart0.2.01 of 2See more

acme mosquitto-helm-chart 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
neilpang/acme.sh:3.0.2595809ad43a2
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

2,050
my-music-appmusic-serverVerified publisher0.1.11 of 1See more

my-music-app music-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
abdullahkhabir/radio:latest56526d0cc929
curl@8.3.0-r0
8.4.0-r0

Open the chart page →

1,561
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14

Open the chart page →

12,791
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
curl@7.88.1-10
7.88.1-10+deb12u4

Open the chart page →

12,813
smilencsaVerified publisher1.1.04 of 23See more

smile ncsa 1.1.0

4 of the 23 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
socialmediamacroscope/preprocessing:0.1.3ca863306314b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4

Open the chart page →

109,294
swaggerncsaVerified publisher1.0.11 of 1See more

swagger ncsa 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:v4.15.511b20aebb92c
curl@7.83.1-r3
8.4.0-r0

Open the chart page →

1,185
ingress-helm-chartnotesprojectchart0.1.01 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
curl@8.1.2-r0
8.4.0-r0

Open the chart page →

2,956
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4

Open the chart page →

15,187
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14

Open the chart page →

8,090
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.14

Open the chart page →

9,005
commonground-gatewayopencatalogi1.5.32 of 7See more

commonground-gateway opencatalogi 1.5.3

2 of the 7 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
curl@7.83.1-r4
8.4.0-r0
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
curl@7.88.1-10
7.88.1-10+deb12u4

Open the chart page →

9,724
probuilderopenfaas0.2.01 of 2See more

probuilder openfaas 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
moby/buildkit:v0.10.0c2aeafaed434
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

4,751
osm-edgeosm-edgeVerified publisher1.3.91 of 7See more

osm-edge osm-edge 1.3.9

1 of the 7 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
flomesh/pipy-repo:0.90.3-3874975c50e3d9
curl@8.3.0-r0
8.4.0-r0

Open the chart page →

5,589
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.14

Open the chart page →

27,537
blockscoutparadeum-teamVerified publisher0.1.51 of 1See more

blockscout paradeum-team 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
quay.io/netwarps/blockscoutdigest-pinnedbecd3e39360a
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

3,448
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
curl@7.83.1-r4
8.4.0-r0

Open the chart page →

26,840
postgresql-backupphntom0.1.91 of 1See more

postgresql-backup phntom 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
phntom/postgresql-backup-s3:1.0.2249b6488f618b
curl@7.86.0-r1
8.4.0-r0

Open the chart page →

2,556
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.14

Open the chart page →

7,576
k8s-node-image-1-15pnnl-miscscripts0.2.611 of 2See more

k8s-node-image-1-15 pnnl-miscscripts 0.2.61

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.4.0-r0

Open the chart page →

1,786
k8s-node-image-1-16pnnl-miscscripts0.2.711 of 2See more

k8s-node-image-1-16 pnnl-miscscripts 0.2.71

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.4.0-r0

Open the chart page →

2,343
k8s-node-image-1-17pnnl-miscscripts0.2.721 of 2See more

k8s-node-image-1-17 pnnl-miscscripts 0.2.72

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.4.0-r0

Open the chart page →

1,578

Container images carrying it

266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
curl@7.83.1-r1
8.4.0-r0
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
curl@8.1.0-r0
8.4.0-r0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
1
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
curl@7.83.1-r4
8.4.0-r0
1
quay.io/netwarps/blockscoutbecd3e39360a
curl@7.80.0-r0
8.4.0-r0
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
curl@7.80.0-r0
8.4.0-r0
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
curl@8.0.1-r0
8.4.0-r0
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
curl@7.83.1-r3
8.4.0-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
curl@7.87.0-r1
8.4.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
curl@7.83.1-r3
8.4.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.4.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
curl@7.88.1-r1
8.4.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
curl@7.83.1-r2
8.4.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.