StackRadar

CVE-2023-38545

Critical

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.785
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
266
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 266 images.

Affected packageAffected versionsFixed inImages
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+23 more8.4.0-r0198
curldeb7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+6 more7.81.0-1ubuntu1.14, 7.88.1-10+deb12u468
OSV records
ALPINE-CVE-2023-38545DEBIAN-CVE-2023-38545UBUNTU-CVE-2023-38545
Also known as
USN-6429-1

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.14

Open the chart page →

6,232
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.4.0-r0

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u4

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.4.0-r0

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.4.0-r0

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.4.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.4.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38545.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.4.0-r0

Open the chart page →

5,033

Container images carrying it

266 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.4.0-r0
10
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
curl@7.80.0-r6
8.4.0-r0
6
quay.io/devtron/kubectl:latest2ad610626658
curl@7.83.1-r3
8.4.0-r0
6
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
curl@7.83.1-r4
8.4.0-r0
5
hyperledger/fabric-tools:2.4b1194f509085
curl@7.83.1-r6
8.4.0-r0
4
mastercloudapps/planner:v1.2340a950b311b2
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.14
4
codeurjc/planner:v1.0800cf520c245
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.14
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
curl@7.83.1-r4
8.4.0-r0
3
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
curl@7.80.0-r0
8.4.0-r0
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.4.0-r0
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
curl@7.88.1-10
7.88.1-10+deb12u4
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.14
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
3
quay.io/devtron/svn-git-sync:v78e54bc2d261f
curl@7.83.1-r1
8.4.0-r0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
curl@7.83.1-r4
8.4.0-r0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
curl@8.1.2-r0
8.4.0-r0
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.4.0-r0
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
curl@8.2.1-r0
8.4.0-r0
2
cs3org/wopiserver:v9.4.202a9e78757b4
curl@7.88.1-r0
8.4.0-r0
2
daniacobext/airports-frontend:latest9eae4d39fc33
curl@8.1.2-r0
8.4.0-r0
2
dependencytrack/frontend:4.6.124422d762e08
curl@7.83.1-r3
8.4.0-r0
2
devopsjourney1/mywebapp:latestbd1ec6838570
curl@7.83.1-r2
8.4.0-r0
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
curl@7.83.1-r4
8.4.0-r0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u4
2
hashicorp/consul:1.14.2e38576edcdfd
curl@7.80.0-r4
8.4.0-r0
2
istio/proxyv2:1.18.0757d28c24100
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
curl@7.83.1-r5
8.4.0-r0
2
krtk6160/galoy-nostrcc82a694f818
curl@7.87.0-r2
8.4.0-r0
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.4.0-r0
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
curl@7.86.0-r1
8.4.0-r0
2
library/influxdb:2.6.1-alpine44a366dd7724
curl@7.88.1-r1
8.4.0-r0
2
library/python:3.7eedf63967cdb
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u4
2
metabase/metabase:v0.45.21fb334ce4820
curl@7.87.0-r1
8.4.0-r0
2
phpipam/phpipam-cron:v1.5.2f770577cb946
curl@7.80.0-r6
8.4.0-r0
2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
curl@7.80.0-r6
8.4.0-r0
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.14
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
curl@7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.14
2
taigaio/taiga-front:latest570c8792ce80
curl@7.88.1-r1
8.4.0-r0
2
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.4.0-r0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.14
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.14
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.14
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
curl@7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.14
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.4.0-r0
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
curl@7.80.0-r1
8.4.0-r0
2
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
curl@7.80.0-r1
8.4.0-r0
2
abdullahkhabir/radio:latest56526d0cc929
curl@8.3.0-r0
8.4.0-r0
1
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
curl@7.83.1-r2
8.4.0-r0
1
akaunting/akaunting:3.0.1552811b36ec3a
curl@7.88.1-10
7.88.1-10+deb12u4
1
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
curl@7.80.0-r3
8.4.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.