StackRadar

CVE-2023-39410

High

Advisory

Published 29 Sept 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
90
of 17,781 indexed, latest versions
Container images
83
deployed by those charts
Fix available
1 of 1
affected package

Apache Avro Java SDK vulnerable to Improper Input Validation

Carried by container images the latest versions of 90 of 17,781 indexed charts deploy, on 83 images.

Affected packageAffected versionsFixed inImages
avromaven1.7.4, 1.7.6, 1.7.7, 1.8.1+8 more1.11.383
OSV records
GHSA-rhrv-645h-fjfh
Also known as
PYSEC-2023-188

Charts affected

90 by stars
ChartLatestAffected imagesRadar Score
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
avro@1.8.2
1.11.3

Open the chart page →

6,147
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
avro@1.7.7
1.11.3

Open the chart page →

5,639
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
avro@1.7.7
1.11.3
gchq/hdfs:3.3.35ec58edbb2db
avro@1.7.7
1.11.3

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
avro@1.7.7
1.11.3

Open the chart page →

9,342
hdfsgradiant-bigdataVerified publisher0.1.101 of 2See more

hdfs gradiant-bigdata 0.1.10

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.3

Open the chart page →

7,073
hivegradiant-bigdataVerified publisher0.1.63 of 5See more

hive gradiant-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
avro@1.7.7
1.11.3
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.3
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
avro@1.7.7
1.11.3

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
avro@1.7.7
1.11.3

Open the chart page →

6,882
opentsdbgradiant-bigdataVerified publisher0.1.72 of 6See more

opentsdb gradiant-bigdata 0.1.7

2 of the 6 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
avro@1.7.7
1.11.3
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.3

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
avro@1.8.2
1.11.3

Open the chart page →

6,147
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
avro@1.7.7
1.11.3

Open the chart page →

4,556
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
avro@1.11.0
1.11.3

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
avro@1.7.7
1.11.3
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
avro@1.7.7
1.11.3

Open the chart page →

10,540
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
avro@1.9.2
1.11.3

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
avro@1.7.7
1.11.3

Open the chart page →

8,541
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
avro@1.8.2
1.11.3

Open the chart page →

39,349
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
avro@1.8.2
1.11.3

Open the chart page →

37,671
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
avro@1.8.2
1.11.3

Open the chart page →

6,174
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
avro@1.9.2
1.11.3

Open the chart page →

10,777
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
avro@1.10.1
1.11.3

Open the chart page →

2,653
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
avro@1.11.0
1.11.3

Open the chart page →

7,254
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
avro@1.9.2
1.11.3

Open the chart page →

2,391
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
avro@1.8.2
1.11.3

Open the chart page →

15,855
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
avro@1.10.2
1.11.3

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
avro@1.10.2
1.11.3

Open the chart page →

15,675
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
avro@1.7.7
1.11.3

Open the chart page →

8,540
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
avro@1.10.2
1.11.3

Open the chart page →

9,005
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
avro@1.7.7
1.11.3

Open the chart page →

9,606
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
avro@1.11.1
1.11.3

Open the chart page →

1,995
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
avro@1.7.7
1.11.3

Open the chart page →

21,211
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
avro@1.11.1
1.11.3

Open the chart page →

1,597
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
avro@1.9.1
1.11.3

Open the chart page →

10,967
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
avro@1.10.2
1.11.3

Open the chart page →

8,804
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
avro@1.7.7
1.11.3

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
avro@1.7.7
1.11.3

Open the chart page →

13,079
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
avro@1.7.7
1.11.3

Open the chart page →

13,767
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
avro@1.7.7
1.11.3

Open the chart page →

4,240
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
avro@1.10.2
1.11.3

Open the chart page →

12,455
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
avro@1.11.1
1.11.3

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
avro@1.7.6
1.11.3

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39410.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
avro@1.10.0
1.11.3

Open the chart page →

3,424

Container images carrying it

83 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gchq/accumulo:2.0.1c460bb587d6d
avro@1.7.7
1.11.3
1
gradiant/hdfs:3.2.2e3bf364fe713
avro@1.7.7
1.11.3
1
gridgain/community:8.9.11d32d182a0e6a
avro@1.7.4
1.11.3
1
hazelcast/hazelcast:5.3.18fe26efde8e1
avro@1.11.1
1.11.3
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
avro@1.11.0
1.11.3
1
hivemq/hivemq4:dns-4.5.144d194450d48e
avro@1.10.1
1.11.3
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
avro@1.8.2
1.11.3
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
avro@1.11.0
1.11.3
1
library/logstash:7.17.817a4f64e9cf5
avro@1.9.2
1.11.3
1
library/storm:2.4.0bd5d420506d6
avro@1.7.7
1.11.3
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
avro@1.8.2
1.11.3
1
lightbend/spark-history-server:2.4.00bedf37f428a
avro@1.8.2
1.11.3
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
avro@1.9.2
1.11.3
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
avro@1.11.0
1.11.3
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
avro@1.7.7
1.11.3
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
avro@1.7.7
1.11.3
1
sslhep/hive-metastore:3.1.39e80af083079
avro@1.8.2
1.11.3
1
trinodb/trino:45038c6f24ab1a4
avro@1.7.7
1.11.3
1
trinodb/trino:405ee80ab5eeab2
avro@1.7.7
1.11.3
1
vitalii1992/analytics-service:latest8e798836ecea
avro@1.11.0
1.11.3
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
avro@1.11.0
1.11.3
1
wavefronthq/proxy:9.2d1064d28f6eb
avro@1.9.2
1.11.3
1
xeotek/kadeck:4.2.94c6b04d9ce55
avro@1.11.0
1.11.3
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
avro@1.10.2
1.11.3
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
avro@1.7.7
1.11.3
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
avro@1.7.7
1.11.3
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
avro@1.7.7
1.11.3
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
avro@1.7.7
1.11.3
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
avro@1.11.1
1.11.3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
avro@1.7.7
1.11.3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
avro@1.7.7
1.11.3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
avro@1.7.6
1.11.3
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
avro@1.10.2
1.11.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.