StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
zahori-moonzahoriVerified publisher1.0.13 of 3See more

zahori-moon zahori 1.0.1

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,907
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.14

Open the chart page →

3,487
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.81

Open the chart page →

5,852
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,697

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.17.0
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.17.0
1
ctron/hawkbit-operator:0.1.48fdea8f76499
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-3.el8_2.2
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0
1
curlimages/curl:8.1.15af13420d29b
nghttp2@1.51.0-r0
1.51.0-r2
1
curlimages/curl:8.00.19e886c104cae
nghttp2@1.47.0-r0
1.47.0-r2
1
curlimages/curl:8.00.0d1658d9c8ef9
nghttp2@1.47.0-r0
1.47.0-r2
1
curlimages/curl:7.83.1e83fef2d5a03
nghttp2@1.46.0-r0
1.46.0-r2
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed
1
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
0.17.0
1
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
golang.org/x/net@v0.7.0
0.17.0
1
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
0.17.0
1
dannielkil/book-backend:lateste3b479a55a69
tomcat-embed-core@9.0.65
9.0.81
1
dannielkil/book-frontend:latest937993927694
nginx@1.27.1-1~bookworm
no fix listed
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
danuk/telegram-sender:0.0.1026560388070
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
0.17.0
1
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
0.17.0
1
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
0.17.0
1
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
0.17.0
1
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
0.17.0
1
darkobas/ethexporter:latest62e6464491ba
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
darkobas/tokenexporter:latesta0349a0eedf0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
0.17.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0:1.33.0-5.el8_8
0.17.0
1
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.17.0
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
0.17.0
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0:1.33.0-4.el8_4.1
0.17.0
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
0.17.0
1
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
0.17.0
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
0.17.0
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
0.17.0
1
dellcloud/category:distributed02fc234353a9
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
1
dellcloud/pages:1.04d2eb25b9225
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.43
1.40.0-1ubuntu0.2
9.0.81
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
0:1.33.0-4.el8_6.1
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.