StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,797 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,797 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
zahori-moonzahoriVerified publisher1.0.13 of 3See more

zahori-moon zahori 1.0.1

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,908
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.14

Open the chart page →

3,487
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.81

Open the chart page →

5,852
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

6,017
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,697

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
1
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.8.0
0.17.0
1
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.17.0
1
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.17.0
1
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.17.0
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
0.17.0
1
kudobuilder/controller:v0.9.069072d979708
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
0.17.0
1
kuzwolka/aws9:main1ad759b961b1
nginx@1.27.5-1~bookworm
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
nginx@1.27.5-1~bookworm
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
nginx@1.27.5-1~bookworm
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
nginx@1.27.5-1~bookworm
no fix listed
1
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
nghttp2@1.51.0-r1
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
1.51.0-r2
0.17.0
1
kyso/jupyter-diff:latest82299a9e5a86
nghttp2@1.51.0-r1
1.51.0-r2
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
nghttp2@1.51.0-r0
1.51.0-r2
1
ladeit/ladeit:latest962b665ffe82
tomcat-embed-core@9.0.13
9.0.81
1
langflowai/langflow-frontend:latest54f67f1961fe
nginx@1.28.0-1~bookworm
no fix listed
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
tomcat-embed-core@9.0.38
9.0.81
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
tomcat-embed-core@9.0.38
9.0.81
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
tomcat-embed-core@9.0.44
9.0.81
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
tomcat-embed-core@9.0.56
9.0.81
1
lavandadelpatio/tmdb:0.0.2f36af885e915
tomcat-embed-core@9.0.44
9.0.81
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
tomcat-embed-core@10.1.7
10.1.14
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
0.17.0
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
0.17.0
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
0.17.0
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
0.17.0
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
0.17.0
1
library/caddy:2.660fb54d36b4b
golang.org/x/net@v0.7.0
0.17.0
1
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
library/caddy:2.4.5874405536b3e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
library/cassandra:3.11.10b095ff3248c6
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
library/docker:24.0.2-dind1d148deae16a
golang.org/x/net@v0.8.0
0.17.0
1
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
library/docker:23.0.6-dindafa5d5134900
golang.org/x/net@v0.8.0
0.17.0
1
library/docker:23.0.1-dindd9a0fd8bdd15
golang.org/x/net@v0.4.0
0.17.0
1
library/elasticsearch:7.17.0332c6d416808
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/elasticsearch:7.17.8fdc73b3249c1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/flink:1.14.6-scala_2.122461f02672b3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
library/httpd:2.4.54ee2117e77c35
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.