CVE-2023-44487
HighKEVAdvisory
Published 10 Oct 2023In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 1.000
- 100th percentile
- CISA KEV
- Listed
- since 10 Oct 2023
- Charts affected
- 2,220
- of 17,828 indexed, latest versions
- Container images
- 2,579
- deployed by those charts
- Fix available
- 21 of 23
- affected packages
Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update
Carried by container images the latest versions of 2,220 of 17,828 indexed charts deploy, on 2,579 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nghttp2deb | 1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more | 1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more | 589 |
| nghttp2apk | 1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more | 1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0 | 220 |
| nghttp2rpm | 1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+8 more | 0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more | 183 |
| nginxdeb | 1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+15 more | no fix listed | 54 |
| nginxapk | 1.20.2-r0, 1.22.0-r0, 1.22.0-r1, 1.22.1-r0+2 more | 1.20.2-r2, 1.22.1-r1, 1.24.0-r7 | 15 |
| nodebitnami | 18.4.0-0, 18.7.0-1, 18.12.1-0, 18.13.0-0+2 more | 18.18.2 | 10 |
| nodejsrpm | 1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd42762 | 1:16.20.2-3.module+el8.8.0+20386+0b1f3093 | 8 |
| nodejs-packagingrpm | 23-3.module+el8.3.0+6519+9f98ed83 | 0:26-1.module+el8.8.0+19857+6d2a104d | 6 |
| nodejsdeb | 8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.3 | 8.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm2 | 4 |
| nginxrpm | 1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el9 | 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0 | 3 |
| nodejs-nodemonrpm | 1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca87034 | 0:3.0.1-1.module+el8.8.0+19764+7eed1ca3 | 3 |
| lighttpdapk | 1.4.64-r0 | 1.4.73-r0 | 2 |
| Node.jsbitnami | 20.4.0, 20.5.1 | 18.18.2 | 2 |
| varnishdeb | 7.5.0, 7.6.3-1~bookworm | no fix listed | 2 |
| Apache Tomcatbitnami | 9.0.80 | 8.5.94 | 1 |
| tomcatbitnami | 9.0.80-1 | 8.5.94 | 1 |
| varnishapk | 7.3.1-r1 | 7.4.2-r0 | 1 |
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+185 more | 0.17.0 | 1,633 |
| tomcat-embed-coremaven | 8.5.4, 8.5.6, 8.5.11, 8.5.14+52 more | 8.5.94, 9.0.81, 10.1.14 | 166 |
| http2-commonmaven | 9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+11 more | 9.4.53, 11.0.17 | 21 |
| http2-servermaven | 9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more | 9.4.53, 11.0.17 | 17 |
| tomcat-coyotemaven | 8.5.38, 8.5.41, 8.5.43, 8.5.47+8 more | 8.5.94, 9.0.81 | 13 |
| akka-http-core_2.12maven | 10.1.11 | 10.5.3 | 1 |
- OSV records
- ALPINE-CVE-2023-44487BIT-node-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
- Also known as
- BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3
Charts affected
2,220 by stars
Container images carrying it
2,579 by charts deploying them
A fixed version is listed for 21 of the 23 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| alpine/ | fc059f056ad0 | nghttp2 golang.org/ | 1.57.0-r0 0.17.0 | 1 |
| altinity/ | 7a85f522c5bc | nghttp2 golang.org/ | 0:1.33.0-5.el8_8 0.17.0 | 1 |
| altinity/ | 8f0f582d41f0 | nghttp2 golang.org/ | 0:1.33.0-5.el8_8 0.17.0 | 1 |
| altinity/ | db7dde971407 | golang.org/ | 0.17.0 | 1 |
| altinity/ | 1a46d104406d | nghttp2 golang.org/ | 0:1.33.0-5.el8_8 0.17.0 | 1 |
| altinity/ | 85b4fdbae053 | golang.org/ | 0.17.0 | 1 |
| amazon/ | d8ab0eef5074 | golang.org/ | 0.17.0 | 1 |
| amazon/ | e745d1783c93 | golang.org/ | 0.17.0 | 1 |
| ambassador/ | 2a4598b03a6a | golang.org/ | 0.17.0 | 1 |
| ambassador/ | b7eb1be3345d | golang.org/ | 0.17.0 | 1 |
| ambassador/ | 5fc571509b8c | golang.org/ | 0.17.0 | 1 |
| anchore/ | bde9eedf639d | nghttp2 golang.org/ | 0:1.33.0-4.el8_4.1 0.17.0 | 1 |
| anchore/ | ed9b3badd17c | nghttp2 | 0:1.33.0-3.el8_1.2 | 1 |
| anchore/ | 8aad6d0912dd | golang.org/ | 0.17.0 | 1 |
| andrcuns/ | b4a8eb20581a | golang.org/ | 0.17.0 | 1 |
| andreacioni/ | 2938b310090a | golang.org/ nghttp2 | 0.17.0 1.43.0-1+deb11u1 | 1 |
| andrianrf/ | 047a7837651e | nginx | 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1 | 1 |
| andrianrf/ | 6036614803d4 | nghttp2 tomcat-embed-core | 0:1.43.0-5.el9_2.1 9.0.81 | 1 |
| andrianrf/ | 46abe878d9d8 | tomcat-embed-core | 9.0.81 | 1 |
| andrianrf/ | b63fdb51d39d | tomcat-embed-core | 9.0.81 | 1 |
| andrianrf/ | ba560086ce15 | tomcat-embed-core | 9.0.81 | 1 |
| andrianrf/ | 7da47f525c7d | nghttp2 tomcat-embed-core | 0:1.43.0-5.el9_2.1 9.0.81 | 1 |
| anguda/ | c435285fc241 | nghttp2 tomcat-coyote tomcat-embed-core | 1.40.0-1ubuntu0.2 8.5.94 8.5.94 | 1 |
| anonaddy/ | 957a95565166 | nghttp2 nginx | 1.47.0-r2 1.22.1-r1 | 1 |
| ansgroup/ | cd6b0ef2b309 | golang.org/ | 0.17.0 | 1 |
| anuja9431/ | 994f35723cb4 | http2-common http2-server | 9.4.53 9.4.53 | 1 |
| apache/ | c010ea7d1694 | golang.org/ | 0.17.0 | 1 |
| apache/ | 412f92cde0b3 | golang.org/ | 0.17.0 | 1 |
| apache/ | 3bb13d14f64a | nghttp2 golang.org/ | 0:1.33.0-4.el8_6.1 0.17.0 | 1 |
| apache/ | 1f96558fd292 | tomcat-embed-core nghttp2 | 8.5.94 1.43.0-1+deb11u1 | 1 |
| apache/ | af361b20bec0 | http2-common | 9.4.53 | 1 |
| apache/ | 8647309f95d1 | tomcat-embed-core | 8.5.94 | 1 |
| apache/ | afa47bf1692a | nghttp2 | 1.40.0-1ubuntu0.2 | 1 |
| apachepinot/ | 0018bb04ced7 | nghttp2 | 1.43.0-1+deb11u1 | 1 |
| apachepulsar/ | 16f9fdab3fa6 | nghttp2 http2-common http2-server | 1.43.0-1ubuntu0.1 9.4.53 9.4.53 | 1 |
| apachepulsar/ | 3b262ab7a7d9 | nghttp2 http2-common http2-server | 1.40.0-1ubuntu0.2 9.4.53 9.4.53 | 1 |
| apachepulsar/ | d056c89b7131 | nghttp2 http2-common http2-server | 1.40.0-1ubuntu0.2 9.4.53 9.4.53 | 1 |
| apachepulsar/ | d538416d5afe | nghttp2 http2-common http2-server | 1.40.0-1ubuntu0.2 9.4.53 9.4.53 | 1 |
| apache/ | 434d8398f996 | tomcat-embed-core | 8.5.94 | 1 |
| apache/ | 5ac2a4e0f627 | tomcat-embed-core | 8.5.94 | 1 |
| apache/ | 79b41e2956de | tomcat-embed-core | 8.5.94 | 1 |
| apache/ | c8fb51195444 | tomcat-embed-core | 9.0.81 | 1 |
| apache/ | ffe68d6b99c0 | golang.org/ | 0.17.0 | 1 |
| apache/ | e2be712fc4f4 | tomcat-embed-core | 9.0.81 | 1 |
| apache/ | 133d35d2c263 | nghttp2 golang.org/ | 1.43.0-1ubuntu0.1 0.17.0 | 1 |
| apache/ | 641237e0299b | golang.org/ | 0.17.0 | 1 |
| apache/ | b4ec8c18d079 | nghttp2 golang.org/ | 1.40.0-1ubuntu0.2 0.17.0 | 1 |
| apache/ | 295f1dc87d98 | nghttp2 | 1.43.0-1ubuntu0.1 | 1 |
| apache/ | 67d50e4deff4 | golang.org/ tomcat-embed-core | 0.17.0 8.5.94 | 1 |
| apache/ | 80530f0308a5 | nghttp2 | 1.40.0-1ubuntu0.2 | 1 |