StackRadar

CVE-2023-44270

Medium

Advisory

Published 29 Sept 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
108
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS line return parsing error

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 108 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+31 more8.4.31107
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-7fh5-64p2-3v2jUBUNTU-CVE-2023-44270

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
8.4.31

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@7.0.39
8.4.31

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.4.31

Open the chart page →

3,143
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
postcss@8.4.14
8.4.31

Open the chart page →

4,820
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
postcss@7.0.21
8.4.31

Open the chart page →

3,696
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.4.31

Open the chart page →

7,574
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.4.31

Open the chart page →

2,460
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.4.31

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.4.31

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
postcss@6.0.23
8.4.31

Open the chart page →

3,881
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
postcss@8.4.6
8.4.31

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
postcss@7.0.39
8.4.31

Open the chart page →

20,270
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
postcss@7.0.35
8.4.31

Open the chart page →

4,661
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
postcss@6.0.23
8.4.31

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.4.31

Open the chart page →

22,665

Container images carrying it

108 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.4.31
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.4.31
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
8.4.31
2
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
8.4.31
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
postcss@7.0.36
8.4.31
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
8.4.31
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
postcss@7.0.39
8.4.31
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
postcss@7.0.39
8.4.31
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
postcss@7.0.39
8.4.31
2
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.4.31
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.4.31
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.4.31
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
8.4.31
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
8.4.31
1
apimap/developer:v1.3.1406d3858e20c
postcss@7.0.39
8.4.31
1
apimap/portal:v2.4.0041a4790c65c
postcss@8.4.14
8.4.31
1
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.36
8.4.31
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
8.4.31
1
assistiot/open_api_frontend:1.0.1f11d82defc70
postcss@8.4.21
8.4.31
1
baserow/baserow:1.30.1df0c42eb67e8
postcss@7.0.39
8.4.31
1
ccjacobs14/amazon:59a9b14a6f09e
postcss@8.4.23
8.4.31
1
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
8.4.31
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postcss@6.0.23
8.4.31
1
codetogether/codetogether:latest4348c8a38752
postcss@7.0.39
8.4.31
1
coldatom/containers-security-front:latest7c2fbbb41bcf
postcss@7.0.39
8.4.31
1
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
8.4.31
1
daskdev/dask-notebook:1.1.0052630f5ca04
postcss@5.2.18
8.4.31
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
postcss@8.4.14
8.4.31
1
ethersphere/onboarding-faucet:0.3.0513154aab230
postcss@8.4.5
8.4.31
1
ethpandaops/blobscan:latest7a9ab6370657
postcss@8.4.14
8.4.31
1
factly/mande-web:0.34.1742355964b0e
postcss@8.4.14
8.4.31
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
postcss@8.4.14
8.4.31
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@6.0.22
8.4.31
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
postcss@7.0.39
8.4.31
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.4.31
1
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.4.31
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
postcss@7.0.39
8.4.31
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
8.4.31
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
postcss@6.0.23
8.4.31
1
ibmcom/microclimate-portal:latested5505e5c7ec
postcss@6.0.17
8.4.31
1
jayfong/yapi:1.10.2163e5d621910
postcss@5.2.18
8.4.31
1
joplin/server:3.0-beta52af57880c0e
postcss@8.4.24
8.4.31
1
joplin/server:2.14.2-betab87564ef34e9
postcss@8.4.24
8.4.31
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-postcss@8.4.31+~cs8.0.26-1
no fix listed
1
keyoxide/keyoxide:stable96f27a71269d
postcss@8.4.11
8.4.31
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postcss@7.0.39
8.4.31
1
konradkleine/docker-registry-frontend:v2181aad54ee64
postcss@4.1.16
8.4.31
1
kyleslugg/klusterview:latestba8c36dfdfbd
postcss@8.4.24
8.4.31
1
kyso/kyso-front:lateste52595c5c16f
postcss@8.4.30
8.4.31
1
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
8.4.31
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.