StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,790 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,790 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
0.17.0

Open the chart page →

2,962
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
nghttp2@1.43.0-5.el9_2.1
tomcat-embed-core@9.0.68
0:1.43.0-5.el9_3.1
9.0.81

Open the chart page →

9,885
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.55
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

10,159
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
nginx@1.22.1-9+deb12u4
no fix listed

Open the chart page →

5,508
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

6,085
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.17.0

Open the chart page →

2,835
jaeger-collectorromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-collector romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

1,854
jaeger-queryromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-query romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

1,797
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

6,918
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,567
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

13,028
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
nginx@1.29.0-1~bookworm
no fix listed

Open the chart page →

5,321
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

13,562
rabbitmq-operatorsagikazarmarkVerified publisher0.0.31 of 1See more

rabbitmq-operator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0

Open the chart page →

2,001
ntfysarab97Verified publisher0.1.71 of 1See more

ntfy sarab97 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

1,766
scienceboxsciencebox0.0.72 of 17See more

sciencebox sciencebox 0.0.7

2 of the 17 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0

Open the chart page →

6,587
iopsciencemeshVerified publisher0.4.02 of 2See more

iop sciencemesh 0.4.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
0.17.0
cs3org/wopiserver:v9.4.202a9e78757b4
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

4,052
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
tomcat-embed-core@8.5.34
8.5.94
seldonio/cluster-manager:0.2.729e362bb1ba2
tomcat-embed-core@8.5.34
8.5.94

Open the chart page →

13,798
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

4,287
clickhousesignoz24.1.183 of 3See more

clickhouse signoz 24.1.18

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
0.17.0
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
0.17.0
signoz/zookeeper:3.7.1fcc4a3288154
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

4,697
cosignedsigstoreVerified publisher0.1.232 of 2See more

cosigned sigstore 0.1.23

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/projectsigstore/cosigneddigest-pinned784518ff3ee7
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
gcr.io/projectsigstore/policy-webhookdigest-pinned82940e8c3e0d
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0

Open the chart page →

5,118
scaffoldsigstoreVerified publisher0.6.1151See more

scaffold sigstore 0.6.115

1 container image this version deploys carries CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0:1.33.0-5.el8_8
0.17.0
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,420
docker-registry-uislamdev0.0.11 of 1See more

docker-registry-ui slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0

Open the chart page →

2,200
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,301
smallest-self-hostsmallest-self-hostVerified publisher0.2.21 of 12See more

smallest-self-host smallest-self-host 0.2.2

1 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

7,684
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

46,028
smarter-edgesmarterOfficialVerified publisher0.0.151 of 1See more

smarter-edge smarter 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

1,144
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aquasec/trivy:0.43.1944a04445179
nghttp2@1.53.0-r0
golang.org/x/net@v0.11.0
1.57.0-r0
0.17.0

Open the chart page →

14,504
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0

Open the chart page →

2,637
go-ratelimitsoftonic1.0.71 of 3See more

go-ratelimit softonic 1.0.7

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0

Open the chart page →

5,098
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,591
gloosolo-gloo-edge0.0.0-fork4 of 5See more

gloo solo-gloo-edge 0.0.0-fork

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

9,224
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,688
sp-otel-collectorsp-otel-collectorVerified publisher1.1.61 of 1See more

sp-otel-collector sp-otel-collector 1.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,022
sql-operatorsql-operatorOfficialVerified publisher0.11.21 of 1See more

sql-operator sql-operator 0.11.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,594
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,236
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0:1.33.0-4.el8_6.1
0.17.0

Open the chart page →

11,459
mayastorstartechnicaVerified publisher0.2.03 of 13See more

mayastor startechnica 0.2.0

3 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.17.0

Open the chart page →

4,348
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
tomcat-embed-core@9.0.70
9.0.81

Open the chart page →

13,532
ckanstatcan0.0.352 of 8See more

ckan statcan 0.0.35

2 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
nghttp2@1.43.0-1
9.4.53
9.4.53
1.43.0-1+deb11u1
statcan/ckan:2.93921305425b8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

24,984
statpingstatping0.1.141 of 1See more

statping statping 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

3,371
hlf-k8ssubstraVerified publisher10.2.43 of 7See more

hlf-k8s substra 10.2.4

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.0f270dfeee91d
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0

Open the chart page →

12,006
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,332
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

2,597
terraform-controllerterraform-controller0.0.201 of 1See more

terraform-controller terraform-controller 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

3,538
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
golang.org/x/net@v0.7.0
1.52.0-1+deb12u1
0.17.0

Open the chart page →

9,108
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
golang.org/x/net@v0.7.0
1.52.0-1+deb12u1
0.17.0

Open the chart page →

9,108
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

2,245
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
0.17.0

Open the chart page →

5,280

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/net@v0.1.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
mailserver/docker-mailserver:11.0.0e0809756dc96
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
maissacrement/pock8snodejs:0.0.16da0db1159da
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
tomcat-embed-core@10.1.13
10.1.14
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
tomcat-embed-core@10.1.13
10.1.14
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
tomcat-embed-core@10.1.13
10.1.14
1
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
manojchaulagain/go-k8s:0.1.0f237b5f637ae
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
mantlenetworkio/l2geth:v0.4.36bf383d14291
nghttp2@1.46.0-r1
golang.org/x/net@v0.10.0
1.46.0-r2
0.17.0
1
mariadb/maxscale:23.02.256c5e0908148
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-5.el8_8
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/net@v0.4.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
masipcat/wireguard-go:latest696206e5954d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
masipcat/wireguard-go:0.0.20230223769f7bb64694
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
matrixdotorg/synapse:v1.78.0def97fd537d8
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
1
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
1
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
0.17.0
1
mautic/mautic:v4-apache94ea4acf4049
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/net@v0.8.0
0.17.0
1
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/net@v0.8.0
0.17.0
1
mediagis/nominatim:3.7c15e941485ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/net@v0.11.0
0.17.0
1
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
golang.org/x/net@v0.13.0
0.17.0
1
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
1
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0
1
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
1
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
metabase/metabase:v0.46.09ebdc664a6b2
nghttp2@1.51.0-r0
http2-common@11.0.14
http2-server@11.0.14
1.51.0-r2
11.0.17
11.0.17
1
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/net@v0.0.0-20181213202711-891ebc4b82d6
0.17.0
1
mezmohq/vector:1.17.3ad5794b112af
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
michaelepitech/sample-app:latestaf51d61c19f5
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
microcks/microcks:0.8.0e3a3e0c67b09
tomcat-embed-core@8.5.34
8.5.94
1
mide/minecraft-overviewer:latest4eee0dcb715f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.