StackRadar

CVE-2023-39417

High

Advisory

Published 11 Aug 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
167
deployed by those charts
Fix available
10 of 12
affected packages

Postgresql: extension script @substitutions@ within quoting allow sql injection

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 167 images.

Affected packageAffected versionsFixed inImages
postgresqlapk13.1-r2, 13.2-r0, 13.3-r0, 13.4-r0+5 more13.12-r022
postgresql14apk14.1-r5, 14.2-r0, 14.4-r0, 14.5-r0+1 more14.9-r019
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+115.5-0+deb12u119
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+4 more11.21.08
postgresql15apk15.1-r0, 15.2-r0, 15.3-r015.4-r06
PostgreSQLbitnami15.3.011.21.02
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+1 more12.16-0ubuntu0.20.04.116
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+1 more14.9-0ubuntu0.22.04.18
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.049.5.25-0ubuntu0.16.04.1+esm53
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-11deb11.4-1, 11.5-1+deb10u1, 11.7-0+deb10u1, 11.9-0+deb10u1+10 more11.21-0+deb10u259
OSV records
ALPINE-CVE-2023-39417BIT-postgresql-2023-39417DEBIAN-CVE-2023-39417UBUNTU-CVE-2023-39417DLA-3600-1
Also known as
USN-6296-1, USN-6366-1

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

12,802
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
postgresql@13.4-r0
13.12-r0

Open the chart page →

5,687
jsonvisiorlex0.1.01 of 1See more

jsonvisio rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
rlex/jsonvisio:1.9.5cd50ff65118e
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,100
test-helm-app2saam-helm-test0.1.01 of 1See more

test-helm-app2 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
asdkant/fastapi-hello-world:latesta23d8bf7c885
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,770
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

16,620
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,313
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

3,313
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
11.21.0

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

30,687
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2

Open the chart page →

11,554
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

20,223
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
12.16-0ubuntu0.20.04.1

Open the chart page →

12,655
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
postgresql15@15.3-r0
15.4-r0

Open the chart page →

21,005
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
library/node:16.20f77a1aef2da8
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
samajh/alprbackend:latestea742b4372ad
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2
samajh/alprfrontend:latest05ef4fddbb75
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2

Open the chart page →

20,270
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

14,358
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2

Open the chart page →

5,514
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2

Open the chart page →

2,670
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
postgresql14@14.2-r0
14.9-r0

Open the chart page →

7,552
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
postgresql@13.5-r0
13.12-r0

Open the chart page →

22,665
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
postgresql@13.4-r0
13.12-r0

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
postgresql@13.5-r0
13.12-r0

Open the chart page →

2,534
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-39417.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
postgresql@13.4-r0
13.12-r0

Open the chart page →

3,697

Container images carrying it

167 by charts deploying them

A fixed version is listed for 10 of the 12 affected packages.

Container imageDigestPackageFixed inUsed by
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.21-0+deb10u2
7
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
postgresql@15.4.0-6
11.21.0
4
assistiot/dlt_api:2.0.0e36a8922fa0c
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
3
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
postgresql@15.3.0-3
PostgreSQL@15.3.0
11.21.0
11.21.0
3
amancevice/superset:0.35.212a0a9e66550
postgresql-11@11.5-1+deb10u1
11.21-0+deb10u2
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
11.21.0
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
2
library/python:3.7eedf63967cdb
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
postgresql@13.4-r0
13.12-r0
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
9.5.25-0ubuntu0.16.04.1+esm5
2
osixia/openldap:1.4.0ccd95cc6e61e
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2
2
pecan/db:latest9a1cdc3a9ccb
postgresql14@14.1-r5
14.9-r0
2
privatebin/pdo:1.3.500466418121c
postgresql14@14.2-r0
14.9-r0
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.9-0ubuntu0.22.04.1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.9-0ubuntu0.22.04.1
2
afrank/mozalert-controller:latestd463c37b08d7
postgresql-11@11.7-0+deb10u1
11.21-0+deb10u2
1
akaunting/akaunting:3.0.1552811b36ec3a
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
alerta/alerta-web:8.5.04786b9eaa606
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2
1
alexeyr7/sf-test-app:latestdf0b41fdbd53
postgresql14@14.4-r0
14.9-r0
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
postgresql-15@15.4-2.pgdg120+1
15.5-0+deb12u1
1
arfath29/3-tier-app-backend:latestee0750b18406
postgresql-11@11.19-0+deb10u1
11.21-0+deb10u2
1
arfath29/3-tier-app-frontend:latest384b3e377f47
postgresql-11@11.19-0+deb10u1
11.21-0+deb10u2
1
arturisimo/server-urjc:v1.0d8dc4430531e
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2
1
asdkant/fastapi-hello-world:latesta23d8bf7c885
postgresql-11@11.9-0+deb10u1
11.21-0+deb10u2
1
assistiot/dlt_api:2.1.0c8a170683be7
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
avinash263/pyredis263:latestaa2b8727f1a6
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
postgresql-11@11.11-0+deb10u1
11.21-0+deb10u2
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
postgresql-11@11.16-0+deb10u1
11.21-0+deb10u2
1
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
postgresql@15.2.0-4
11.21.0
1
bitnamilegacy/postgresql:15.3.0-debian-11-r775f4cf61668e5
postgresql@15.3.0-9
PostgreSQL@15.3.0
11.21.0
11.21.0
1
bitnamilegacy/postgresql:11.8.0c3f10b41989f
postgresql@11.8.0-10
11.21.0
1
camptocamp/bucket-cloner:latestacfafc308d88
postgresql-11@11.12-0+deb10u1
11.21-0+deb10u2
1
camptocamp/ekorre:0.1.035c91d5fda04
postgresql-11@11.5-1+deb10u1
11.21-0+deb10u2
1
cdignam/kodiak:v0.54.05a6a55b39cee
postgresql-11@11.4-1
11.21-0+deb10u2
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
postgresql-11@11.5-1+deb10u1
11.21-0+deb10u2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postgresql-11@11.17-0+deb10u1
11.21-0+deb10u2
1
dacinfomotion/h2p:latest68fa393b472c
postgresql-11@11.20-0+deb10u1
11.21-0+deb10u2
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
postgresql14@14.4-r0
14.9-r0
1
edoburu/pgbouncer:1.12.0abc0a4123a81
postgresql@13.4-r0
13.12-r0
1
evgkrsk/postgres-controller:0.6.237f0e1f435c3
postgresql15@15.1-r0
15.4-r0
1
firefart/requesttracker:5.0.40d6249906d8c
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
fireflyiii/core:version-5.6.142f4283bd0cf7
postgresql-11@11.14-0+deb10u1
11.21-0+deb10u2
1
fossology/fossology:4.2.18bd1f22ba7bb
postgresql-11@11.18-0+deb10u1
11.21-0+deb10u2
1
galaxy/galaxy-stable:v18.018e577a626dfd
postgresql-9.3@9.3.22-0ubuntu0.14.04
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
postgresql-10@10.14-0ubuntu0.18.04.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.