StackRadar

CVE-2023-39418

Medium

Advisory

Published 11 Aug 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
52
of 17,781 indexed, latest versions
Container images
48
deployed by those charts
Fix available
5 of 5
affected packages

Postgresql: merge fails to enforce update or select row security policies

Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 48 images.

Affected packageAffected versionsFixed inImages
postgresql14apk14.1-r5, 14.2-r0, 14.4-r0, 14.5-r0+1 more14.9-r019
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+115.5-0+deb12u119
postgresql15apk15.1-r0, 15.2-r0, 15.3-r015.4-r06
postgresqlbitnami15.2.0-4, 15.3.0-3, 15.3.0-9, 15.4.0-615.4.04
PostgreSQLbitnami15.3.015.4.02
OSV records
ALPINE-CVE-2023-39418BIT-postgresql-2023-39418DEBIAN-CVE-2023-39418

Charts affected

52 by stars
ChartLatestAffected imagesRadar Score
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39418.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1

Open the chart page →

14,358
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-39418.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
postgresql14@14.2-r0
14.9-r0

Open the chart page →

7,552

Container images carrying it

48 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
postgresql@15.4.0-6
15.4.0
4
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
postgresql@15.3.0-3
PostgreSQL@15.3.0
15.4.0
15.4.0
3
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
2
library/python:3.7eedf63967cdb
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
2
pecan/db:latest9a1cdc3a9ccb
postgresql14@14.1-r5
14.9-r0
2
privatebin/pdo:1.3.500466418121c
postgresql14@14.2-r0
14.9-r0
2
akaunting/akaunting:3.0.1552811b36ec3a
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
alexeyr7/sf-test-app:latestdf0b41fdbd53
postgresql14@14.4-r0
14.9-r0
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
postgresql-15@15.4-2.pgdg120+1
15.5-0+deb12u1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
avinash263/pyredis263:latestaa2b8727f1a6
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
postgresql@15.2.0-4
15.4.0
1
bitnamilegacy/postgresql:15.3.0-debian-11-r775f4cf61668e5
postgresql@15.3.0-9
PostgreSQL@15.3.0
15.4.0
15.4.0
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
postgresql14@14.4-r0
14.9-r0
1
evgkrsk/postgres-controller:0.6.237f0e1f435c3
postgresql15@15.1-r0
15.4-r0
1
firefart/requesttracker:5.0.40d6249906d8c
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
ihatemoney/ihatemoney:5.2.0457fda1feb32
postgresql14@14.2-r0
14.9-r0
1
kfirfer/scripts:0.0.2481e5c4e5d70e
postgresql14@14.5-r0
14.9-r0
1
library/postgres:15.38775adb39f0d
postgresql-15@15.3-1.pgdg120+1
15.5-0+deb12u1
1
librenms/librenms:22.4.14f1f3d667cc7
postgresql14@14.2-r0
14.9-r0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
postgresql15@15.2-r0
15.4-r0
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
postgresql14@14.8-r0
14.9-r0
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
postgresql14@14.5-r0
14.9-r0
1
pgpool/pgpool:latest3782cbf9bb0c
postgresql15@15.2-r0
15.4-r0
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
postgresql15@15.1-r0
15.4-r0
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
postgresql14@14.5-r0
14.9-r0
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
temporalio/admin-tools:1.22.0836af062af30
postgresql15@15.3-r0
15.4-r0
1
thongngo3301/stakefish:latesta341af5976e3
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
vlebediantsev/notes-admin-front:latest007c6670ff48
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
vlebediantsev/notes-project-front:latest945675fd2636
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
volkerraschek/postfixadmin-fetchmail:0.3.0e4cf12c6249d
postgresql15@15.1-r0
15.4-r0
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
postgresql14@14.2-r0
14.9-r0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
postgresql14@14.5-r0
14.9-r0
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
postgresql14@14.5-r0
14.9-r0
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.5-0+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.