StackRadar

CVE-2023-39417

High

Advisory

Published 11 Aug 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
167
deployed by those charts
Fix available
10 of 12
affected packages

Postgresql: extension script @substitutions@ within quoting allow sql injection

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 167 images.

Affected packageAffected versionsFixed inImages
postgresqlapk13.1-r2, 13.2-r0, 13.3-r0, 13.4-r0+5 more13.12-r022
postgresql14apk14.1-r5, 14.2-r0, 14.4-r0, 14.5-r0+1 more14.9-r019
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+115.5-0+deb12u119
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+4 more11.21.08
postgresql15apk15.1-r0, 15.2-r0, 15.3-r015.4-r06
PostgreSQLbitnami15.3.011.21.02
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+1 more12.16-0ubuntu0.20.04.116
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+1 more14.9-0ubuntu0.22.04.18
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.049.5.25-0ubuntu0.16.04.1+esm53
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-11deb11.4-1, 11.5-1+deb10u1, 11.7-0+deb10u1, 11.9-0+deb10u1+10 more11.21-0+deb10u259
OSV records
ALPINE-CVE-2023-39417BIT-postgresql-2023-39417DEBIAN-CVE-2023-39417UBUNTU-CVE-2023-39417DLA-3600-1
Also known as
USN-6296-1, USN-6366-1

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

12,802
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
postgresql@13.4-r0
13.12-r0

Open the chart page →

5,687
jsonvisiorlex0.1.01 of 1See more

jsonvisio rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
rlex/jsonvisio:1.9.5cd50ff65118e
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,100
test-helm-app2saam-helm-test0.1.01 of 1See more

test-helm-app2 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
asdkant/fastapi-hello-world:latesta23d8bf7c885
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,770
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

16,620
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,313
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,313
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
11.21.0

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

30,687
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2

Open the chart page →

11,554
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

20,223
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

12,655
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
postgresql15@15.3-r0
15.4-r0

Open the chart page →

21,005
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
library/node:16.20f77a1aef2da8
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
samajh/alprbackend:latestea742b4372ad
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2
samajh/alprfrontend:latest05ef4fddbb75
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2

Open the chart page →

20,270
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

14,358
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

5,514
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,670
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
postgresql14@14.2-r0
14.9-r0

Open the chart page →

7,552
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
postgresql@13.5-r0
13.12-r0

Open the chart page →

22,665
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
postgresql@13.4-r0
13.12-r0

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
postgresql@13.5-r0
13.12-r0

Open the chart page →

2,534
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
postgresql@13.4-r0
13.12-r0

Open the chart page →

3,697

Container images carrying it

167 by charts deploying them

A fixed version is listed for 10 of the 12 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/grofers/legend:0.1d6e901ad0ebd
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
postgresql@13.5-r0
13.12-r0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
postgresql14@14.5-r0
14.9-r0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
postgresql@13.5-r0
13.12-r0
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postgresql-11@11.13-0+deb10u1
11.21-0+deb10u2
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
postgresql@13.4-r0
13.12-r0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
postgresql@13.4-r0
13.12-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.