StackRadar

CVE-2023-39319

Medium

Advisory

Published 7 Sept 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,868
of 17,813 indexed, latest versions
Container images
2,126
deployed by those charts
Fix available
1 of 2
affected packages

Improper handling of special tags within script contexts in html/template

Carried by container images the latest versions of 1,868 of 17,813 indexed charts deploy, on 2,126 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+107 more1.20.82,126
OSV records
DEBIAN-CVE-2023-39319GO-2023-2043
Also known as
BIT-golang-2023-39319

Charts affected

1,868 by stars
ChartLatestAffected imagesRadar Score
podgrabnicholaswildeVerified publisher0.1.01 of 1See more

podgrab nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.20.8

Open the chart page →

2,402
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
stdlib@go1.17.11
1.20.8

Open the chart page →

22,445
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
stdlib@go1.16.12
1.20.8

Open the chart page →

23,648
staticnicholaswildeVerified publisher1.0.01 of 1See more

static nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.20.8

Open the chart page →

1,155
todonicholaswildeVerified publisher0.1.01 of 1See more

todo nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.20.8

Open the chart page →

1,230
twtxtnicholaswildeVerified publisher1.0.01 of 1See more

twtxt nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
stdlib@go1.16.5
1.20.8

Open the chart page →

2,334
wikinicholaswildeVerified publisher1.0.01 of 1See more

wiki nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
stdlib@go1.16.5
1.20.8

Open the chart page →

1,789
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
stdlib@go1.17.6
1.20.8

Open the chart page →

2,063
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.20.8

Open the chart page →

1,841
airflownineinfra-charts1.12.12 of 4See more

airflow nineinfra-charts 1.12.1

2 of the 4 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.20.8
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.20.8

Open the chart page →

2,260
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
stdlib@go1.19.13
1.20.8

Open the chart page →

870
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
stdlib@go1.20.3
1.20.8
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
stdlib@go1.20.3
1.20.8
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
stdlib@go1.20.3
1.20.8
quay.io/minio/directpv:v4.0.84560083eb77d
stdlib@go1.21.0
1.20.8
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
stdlib@go1.20.3
1.20.8

Open the chart page →

7,071
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.20.8

Open the chart page →

3,978
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.20.8

Open the chart page →

1,440
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
stdlib@go1.18.5
1.20.8

Open the chart page →

6,627
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
stdlib@go1.19.3
1.20.8

Open the chart page →

2,921
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
stdlib@go1.18.5
1.20.8

Open the chart page →

4,785
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
stdlib@go1.16.15
1.20.8

Open the chart page →

1,490
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
stdlib@go1.20.6
1.20.8
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.20.8
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.20.8
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
stdlib@go1.21.0
1.20.8
quay.io/prometheus/pushgateway:v1.6.05111de00e969
stdlib@go1.20.4
1.20.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
stdlib@go1.20.7
1.20.8

Open the chart page →

7,759
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.20.8

Open the chart page →

22,829
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.20.8
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.20.8

Open the chart page →

2,957
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.20.8

Open the chart page →

4,559
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
stdlib@go1.20.4
1.20.8

Open the chart page →

2,257
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
stdlib@go1.13.10
1.20.8

Open the chart page →

7,539
clusterfannousefreakVerified publisher0.1.21 of 1See more

clusterfan nousefreak 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/nousefreak/clusterfan:v0.1.04ea05e2a7b57
stdlib@go1.17.5
1.20.8

Open the chart page →

1,791
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
stdlib@go1.15.5
1.20.8

Open the chart page →

4,862
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.20.8

Open the chart page →

2,807
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
stdlib@go1.17.11
1.20.8

Open the chart page →

27,580
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.20.8

Open the chart page →

1,839
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.20.8

Open the chart page →

4,999
observabilitysecobservabilitysec0.0.11 of 2See more

observabilitysec observabilitysec 0.0.1

1 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.20.8

Open the chart page →

1,180
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
stdlib@go1.20.4
1.20.8

Open the chart page →

17,279
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
stdlib@go1.17.10
1.20.8

Open the chart page →

1,608
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
stdlib@go1.19.13
1.20.8

Open the chart page →

2,132
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
stdlib@go1.18.2
1.20.8

Open the chart page →

5,852
aspromokgoloveVerified publisher2.0.01 of 1See more

asprom okgolove 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
okgolove/asprom:1.10.1974d2e5eb150
stdlib@go1.14.11
1.20.8

Open the chart page →

1,870
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
stdlib@go1.13.4
1.20.8

Open the chart page →

8,550
exposecontrollerolli-aiVerified publisher1.0.51 of 1See more

exposecontroller olli-ai 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
olliai/exposecontroller:1.0.5a470d96525e4
stdlib@go1.16.3
1.20.8

Open the chart page →

2,862
k8s-replicatorolli-aiVerified publisher1.3.01 of 1See more

k8s-replicator olli-ai 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
olliai/k8s-replicator:1.3.05716f2a8bd4c
stdlib@go1.17.2
1.20.8

Open the chart page →

2,826
apicurioone-acre-fundVerified publisher2.3.01 of 5See more

apicurio one-acre-fund 2.3.0

1 of the 5 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.20.8

Open the chart page →

18,698
one-green-coreone-green-coreVerified publisher0.0.73 of 8See more

one-green-core one-green-core 0.0.7

3 of the 8 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
stdlib@go1.17.9
1.20.8
library/influxdb:2.0.8ba10ac9ba17a
stdlib@go1.16.5
1.20.8
library/telegraf:1.20.428e98eece020
stdlib@go1.17.3
1.20.8

Open the chart page →

9,586
opa-nginxopa-nginx0.0.32 of 2See more

opa-nginx opa-nginx 0.0.3

2 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
openpolicyagent/opa:0.53.16a58dea59933
stdlib@go1.20.4
1.20.8
richardjennings/opa-nginx:0.0.366424aca125d
stdlib@go1.20.5
1.20.8

Open the chart page →

2,207
opds-shelfopds-shelfVerified publisher0.4.01 of 3See more

opds-shelf opds-shelf 0.4.0

1 of the 3 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
stdlib@go1.17.8
1.20.8

Open the chart page →

4,415
basic-appopen-charts1.0.01 of 1See more

basic-app open-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
ovhplatform/what-is-my-pod:1.0.16d4d455e9aba
stdlib@go1.16.14
1.20.8

Open the chart page →

1,598
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
stdlib@go1.16.3
1.20.8

Open the chart page →

18,035
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
stdlib@go1.13.8
1.20.8

Open the chart page →

3,926
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
stdlib@go1.16.3
1.20.8

Open the chart page →

3,740
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.20.8

Open the chart page →

4,620
volthaopencord2.14.02 of 2See more

voltha opencord 2.14.0

2 of the 2 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
stdlib@go1.16.3
1.20.8
voltha/voltha-rw-core:3.4.87a325316fe59
stdlib@go1.16.3
1.20.8

Open the chart page →

3,825
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2023-39319.

Container imageDigestPackageFixed in
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
stdlib@go1.16.5
1.20.8
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
stdlib@go1.16.3
1.20.8

Open the chart page →

41,189

Container images carrying it

2,126 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
stdlib@go1.19.4
1.20.8
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
stdlib@go1.19.7
1.20.8
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
stdlib@go1.20.4
1.20.8
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
stdlib@go1.18
1.20.8
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
stdlib@go1.18
1.20.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
stdlib@go1.20.5
1.20.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.20.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.20.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.20.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.20.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.20.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.20.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.20.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.20.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.20.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.20.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.20.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.20.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.20.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.20.8
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.