CVE-2023-44270
MediumAdvisory
Published 29 Sept 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 115
- of 17,781 indexed, latest versions
- Container images
- 108
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
PostCSS line return parsing error
Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 108 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| postcssnpm | 4.1.16, 5.2.18, 6.0.17, 6.0.22+31 more | 8.4.31 | 107 |
| node-postcssdeb | 8.4.31+~cs8.0.26-1 | no fix listed | 1 |
- OSV records
- GHSA-7fh5-64p2-3v2jUBUNTU-CVE-2023-44270
Charts affected
115 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| wekanschmitzis | 1.1.1 | 1 of 1See more | 3,638 |
| secret-managersecret-managerVerified publisher | 1.0.0 | 1 of 4See more | 5,497 |
| dashysergiotocaliniVerified publisher | 1.0.0 | 1 of 1See more | 3,143 |
| counter-dhlsikademo | 0.3.0 | 1 of 3See more | 4,820 |
| parkingsikalabs | 0.1.0 | 1 of 1See more | 3,696 |
| sneakerssneakers | 1.0.0 | 1 of 4See more | 7,574 |
| speedtest-trackersoblivionscall | 3.0.4 | 1 of 1See more | 2,460 |
| nordmart-reviewstakaterVerified publisher | 0.0.6 | 1 of 3See more | 11,554 |
| nordmart-review-instancestakaterVerified publisher | 1.0.0 | 1 of 3See more | 11,554 |
| fdi-dotstatsuite-dlmstatcan | 0.3.1 | 1 of 1See more | 3,881 |
| trudesktechpreta | 1.0.0 | 1 of 3See more | 4,017 |
| vehicle-dashboardtest-vehi-dash | 0.1.0 | 1 of 7See more | 20,270 |
| thanhvt27-lab-k8sthanh-vtVerified publisher | 0.1.4 | 1 of 5See more | 4,661 |
| cadencewenerme | 0.23.0 | 1 of 5See more | 10,127 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
Container images carrying it
108 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 254d16af8f71 | postcss | 8.4.31 | 1 |
| ghcr.io/ | 6197516c9d7b | postcss | 8.4.31 | 1 |
| ghcr.io/ | ed07e7ca098d | postcss | 8.4.31 | 1 |
| ghcr.io/ | 5bae30456ddb | postcss | 8.4.31 | 1 |
| quay.io/ | ce6938ff6709 | postcss | 8.4.31 | 1 |
| quay.io/ | 7a4b9fedc724 | postcss | 8.4.31 | 1 |
| quay.io/ | 99ccdfd543e1 | postcss | 8.4.31 | 1 |
| quay.io/ | cb17600883a3 | postcss | 8.4.31 | 1 |