StackRadar

CVE-2023-39417

High

Advisory

Published 11 Aug 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
167
deployed by those charts
Fix available
10 of 12
affected packages

Postgresql: extension script @substitutions@ within quoting allow sql injection

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 167 images.

Affected packageAffected versionsFixed inImages
postgresqlapk13.1-r2, 13.2-r0, 13.3-r0, 13.4-r0+5 more13.12-r022
postgresql14apk14.1-r5, 14.2-r0, 14.4-r0, 14.5-r0+1 more14.9-r019
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+115.5-0+deb12u119
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+4 more11.21.08
postgresql15apk15.1-r0, 15.2-r0, 15.3-r015.4-r06
PostgreSQLbitnami15.3.011.21.02
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+1 more12.16-0ubuntu0.20.04.116
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+1 more14.9-0ubuntu0.22.04.18
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.049.5.25-0ubuntu0.16.04.1+esm53
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-11deb11.4-1, 11.5-1+deb10u1, 11.7-0+deb10u1, 11.9-0+deb10u1+10 more11.21-0+deb10u259
OSV records
ALPINE-CVE-2023-39417BIT-postgresql-2023-39417DEBIAN-CVE-2023-39417UBUNTU-CVE-2023-39417DLA-3600-1
Also known as
USN-6296-1, USN-6366-1

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2

Open the chart page →

4,518
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
postgresql-11@11.5-1+deb10u1
11.21-0+deb10u2

Open the chart page →

3,891
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2

Open the chart page →

6,219
drupalcetic0.1.01 of 1See more

drupal cetic 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
library/drupal:8-apache8a1a3ee83899
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,504
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
postgresql@13.7-r0
13.12-r0

Open the chart page →

2,814
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
postgresql-9.3@9.3.22-0ubuntu0.14.04
no fix listed

Open the chart page →

70,895
nextcloudcloudve1.13.01 of 2See more

nextcloud cloudve 1.13.0

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
library/nextcloud:17.0.0-apache96104cb965fc
postgresql-11@11.5-1+deb10u1
11.21-0+deb10u2

Open the chart page →

3,016
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

5,293
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
firefart/requesttracker:5.0.40d6249906d8c
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

15,380
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
postgresql-10@10.14-0ubuntu0.18.04.1
no fix listed

Open the chart page →

18,863
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
postgresql-10@10.6-0ubuntu0.18.04.1
no fix listed

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed

Open the chart page →

24,335
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,042
pleromaderp0.1.91 of 1See more

pleroma derp 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
postgresql14@14.5-r0
14.9-r0

Open the chart page →

2,707
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,770
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.9-0ubuntu0.22.04.1

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.9-0ubuntu0.22.04.1

Open the chart page →

29,033
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
postgresql14@14.4-r0
14.9-r0

Open the chart page →

2,548
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
postgresql-14@14.6-1.pgdg22.04+1
14.9-0ubuntu0.22.04.1

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
postgresql-14@14.3-1.pgdg22.04+1
14.9-0ubuntu0.22.04.1

Open the chart page →

30,699
glossaryduyet0.1.01 of 1See more

glossary duyet 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/duyet/glossary:0.1.0ae6309fa237d
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2

Open the chart page →

631
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
postgresql14@14.2-r0
14.9-r0

Open the chart page →

7,255
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
timescale/timescaledb-postgis:latest-pg127758704d4a14
postgresql@13.3-r0
13.12-r0

Open the chart page →

11,482
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
postgresql14@14.4-r0
14.9-r0

Open the chart page →

7,534
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
postgresql14@14.2-r0
14.9-r0

Open the chart page →

7,327
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
postgresql-11@11.19-0+deb10u1
11.21-0+deb10u2

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
postgresql-11@11.19-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,744
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2

Open the chart page →

27,096
doraethereum-helm-chartsVerified publisher1.0.121 of 2See more

dora ethereum-helm-charts 1.0.12

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
postgresql@15.3.0-3
PostgreSQL@15.3.0
11.21.0
11.21.0

Open the chart page →

2,991
kodiakfikaworks1.1.41 of 2See more

kodiak fikaworks 1.1.4

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
cdignam/kodiak:v0.54.05a6a55b39cee
postgresql-11@11.4-1
11.21-0+deb10u2

Open the chart page →

3,892
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
postgresql@13.8-r0
13.12-r0

Open the chart page →

1,958
ihatemoneygeek-cookbookVerified publisher1.1.21 of 1See more

ihatemoney geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ihatemoney/ihatemoney:5.2.0457fda1feb32
postgresql14@14.2-r0
14.9-r0

Open the chart page →

1,526
kanboardgeek-cookbookVerified publisher5.2.01 of 1See more

kanboard geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
kanboard/kanboard:v1.2.200b6d33dbbc16
postgresql@13.3-r0
13.12-r0

Open the chart page →

1,688
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
postgresql-12@12.12-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

27,949
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
postgresql@13.4-r0
13.12-r0

Open the chart page →

2,643
privatebingeek-cookbookVerified publisher2.2.01 of 1See more

privatebin geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
privatebin/pdo:1.3.500466418121c
postgresql14@14.2-r0
14.9-r0

Open the chart page →

1,159
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
postgresql@13.4-r0
13.12-r0

Open the chart page →

3,064
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2

Open the chart page →

1,713
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

24,995
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2

Open the chart page →

8,213
dbapphelmcourseVerified publisher0.3.31 of 2See more

dbapp helmcourse 0.3.3

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
library/adminer:4.7143ec8cc2f3a
postgresql@13.1-r2
13.12-r0

Open the chart page →

3,971
privatebinhomelabcihelmchartstestVerified publisher2.1.71 of 1See more

privatebin homelabcihelmchartstest 2.1.7

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
privatebin/pdo:1.3.500466418121c
postgresql14@14.2-r0
14.9-r0

Open the chart page →

1,159
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
postgresql15@15.2-r0
15.4-r0

Open the chart page →

2,628
pgpoolimprowisedVerified publisher1.0.11 of 1See more

pgpool improwised 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
pgpool/pgpool:latest3782cbf9bb0c
postgresql15@15.2-r0
15.4-r0

Open the chart page →

948
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,314
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2

Open the chart page →

7,232
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

16,600
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
postgresql@13.11-r0
13.12-r0

Open the chart page →

2,581

Container images carrying it

167 by charts deploying them

A fixed version is listed for 10 of the 12 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/grofers/legend:0.1d6e901ad0ebd
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
postgresql@13.5-r0
13.12-r0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
postgresql14@14.5-r0
14.9-r0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
postgresql@13.5-r0
13.12-r0
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postgresql-11@11.13-0+deb10u1
11.21-0+deb10u2
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
postgresql@13.4-r0
13.12-r0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
postgresql@13.4-r0
13.12-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.