StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,803 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,803 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,519
kspanpuckpuck0.2.41 of 1See more

kspan puckpuck 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0

Open the chart page →

1,688
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
nghttp2@1.55.1-r0
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
1.57.0-r0
0.17.0

Open the chart page →

4,221
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0:1.33.0-4.el8_6.1
0.17.0

Open the chart page →

6,674
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0

Open the chart page →

6,556
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

14,624
python-apppython-app-chart0.1.01 of 2See more

python-app python-app-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mnaggar3396/python-app:latest371d8ed84b15
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,397
python-fastapi-postgrespython-fastapi-postgres0.1.01 of 1See more

python-fastapi-postgres python-fastapi-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
archish27/python-fastapi-postgres:latest6610071a2101
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,983
vaultwardenqbittorrent-helm5.4.01 of 1See more

vaultwarden qbittorrent-helm 5.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vaultwarden/server:1.29.1c2849f8189e4
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

680
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
nghttp2@1.39.2-lp151.3.3.1
0.17.0
1.57.0-1.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
nghttp2@1.39.2-lp151.3.3.1
0.17.0
1.57.0-1.1

Open the chart page →

11,954
quarksquarks7.0.1+0.g5396b115 of 5See more

quarks quarks 7.0.1+0.g5396b11

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cfcontainerizationbot/kubecf-kubectl:v1.19.261daa1bba5cb
nghttp2@1.40.0-1.15
1.40.0-150200.12.1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
nghttp2@1.40.0-3.6.3
0.17.0
1.40.0-150000.3.17.1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
nghttp2@1.40.0-3.6.3
0.17.0
1.40.0-150000.3.17.1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
nghttp2@1.40.0-3.6.3
0.17.0
1.40.0-150000.3.17.1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
nghttp2@1.40.0-3.6.3
0.17.0
1.40.0-150000.3.17.1

Open the chart page →

18,202
quarks-jobquarks0.0.124-g03faac81 of 1See more

quarks-job quarks 0.0.124-g03faac8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.17.1

Open the chart page →

1,805
quarks-secretquarks0.0.677-ga060bb61 of 1See more

quarks-secret quarks 0.0.677-ga060bb6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.17.1

Open the chart page →

1,815
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
nghttp2@1.40.0-3.6.3
0.17.0
1.40.0-150000.3.17.1

Open the chart page →

4,011
ingress-controllerqumine0.8.5001 of 1See more

ingress-controller qumine 0.8.500

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,533
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
nginx@1.27.5-1~bookworm
no fix listed

Open the chart page →

4,497
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

21,287
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

4,237
radar-s3-connectorradar-baseVerified publisher0.7.21 of 2See more

radar-s3-connector radar-base 0.7.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/yq:3.2.26f5b9586a93e
nghttp2@1.55.1-r0
1.57.0-r0

Open the chart page →

1,415
pagesranjinigogga1.0.02 of 3See more

pages ranjinigogga 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

3,745
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
oxfordsemantic/rdfox-init:5.6baf570ff968d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,900
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

15,552
pagesrebecca-pages1.0.02 of 3See more

pages rebecca-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

12,383
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

15,299
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

15,299
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0:1.33.0-3.el8_2.2
0.17.0

Open the chart page →

11,446
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-5.el8_8

Open the chart page →

16,389
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.17.3-2.module+el8.4.0+11738+3bd42762
nodejs-nodemon@2.0.3-1.module+el8.3.0+6519+9f98ed83
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:3.0.1-1.module+el8.8.0+19764+7eed1ca3
0.17.0

Open the chart page →

29,566
registry-credsregistry-creds0.2.31 of 1See more

registry-creds registry-creds 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

1,042
remla23-team17remla23-team171.0.02 of 2See more

remla23-team17 remla23-team17 1.0.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

4,448
reportportalreportportal5.7.28 of 8See more

reportportal reportportal 5.7.2

8 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20190424112056-4829fb13d2c6
1.46.0-r2
0.17.0
reportportal/service-api:5.7.29df41f8fb320
tomcat-embed-core@9.0.37
9.0.81
reportportal/service-authorization:5.7.09e73114dbd15
tomcat-embed-core@9.0.37
9.0.81
reportportal/service-auto-analyzer:5.7.295ada4a216ce
nghttp2@1.43.0-1
1.43.0-1+deb11u1
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0
reportportal/service-jobs:5.7.2dc166c58485a
tomcat-embed-core@9.0.43
9.0.81
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
nghttp2@1.43.0-1
1.43.0-1+deb11u1
reportportal/service-ui:5.7.20a08784eb901
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

25,756
resource-manager-operatorresource-manager-operator0.1.01 of 1See more

resource-manager-operator resource-manager-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

1,624
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,501
backup-maker-controllerriotkit-org0.1.21 of 1See more

backup-maker-controller riotkit-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

1,576
haproxy-loadbalanced-redisrivals-spaceVerified publisher0.1.21 of 3See more

haproxy-loadbalanced-redis rivals-space 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
haproxytech/haproxy-alpine:2.6.614e4afa90dfd
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

1,423
rke2-calicorke2-charts3.18.1-1011 of 1See more

rke2-calico rke2-charts 3.18.1-101

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,250
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

5,956
kubernetes-diff-loggerrlex0.1.21 of 1See more

kubernetes-diff-logger rlex 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,454
runtimeclass-controllerrlex0.1.01 of 1See more

runtimeclass-controller rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,180
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
nghttp2@1.47.0-r1
nginx@1.22.1-r0
1.47.0-r2
1.22.1-r1

Open the chart page →

2,972
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

4,047
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
http2-common@9.4.45.v20220203
http2-server@9.4.45.v20220203
0.17.0
9.4.53
9.4.53

Open the chart page →

3,053
easy-olm-operatorrock8sVerified publisher0.0.11 of 1See more

easy-olm-operator rock8s 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

953
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

5,430
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,029
mailserverrock8sVerified publisher0.1.21 of 1See more

mailserver rock8s 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

1,954
resource-binding-operatorrock8sVerified publisher0.1.01 of 1See more

resource-binding-operator rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

917

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
0.17.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
0.17.0
1
postgis/postgis:15-3.3-alpine4738bee21eb6
nghttp2@1.55.1-r0
1.57.0-r0
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
nghttp2@1.47.0-r0
1.47.0-r2
1
pozetroninc/keydb:v6.0.1653ae64f29da8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
0.17.0
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0
1
praravind1801/helmimages:3.0.0f29d637b9ce1
nginx@1.25.3-1~bookworm
no fix listed
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
0.17.0
1
prefapp/nginx-proxified:latestf4d026fd9a26
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
nghttp2@1.51.0-r0
1.51.0-r2
1
project2team4/react:latest3ff031a08887
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
0.17.0
1
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/net@v0.0.0-20220728211354-c7608f3a8462
0.17.0
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
0.17.0
1
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0
1
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/net@v0.10.0
0.17.0
1
prom/prometheus:v2.18.15880ec936055
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
0.17.0
1
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
1
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
1
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0
1
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
0.17.0
1
psorab/elibrary:latest53b68896c4ce
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
punkerside/noroot:v0.0.7be20c81d6ca1
nghttp2@1.47.0-r0
1.47.0-r2
1
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0
1
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
qumine/minecraft-server:v0.1.15c0b650d51132
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.43.0-1ubuntu0.1
0.17.0
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
1
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
0.17.0
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
1
rclone/rclone:1.63.008e1af3c8814
golang.org/x/net@v0.8.0
0.17.0
1
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0
1
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
0.17.0
1
redimp/otterwiki:2778bf30da3da
nginx@1.22.1-9+deb12u9
no fix listed
1
refar/apm-api:v5.7.1241373fa2972
tomcat-embed-core@9.0.37
9.0.81
1
refar/apm-operator-server:v5.7.1e5490f050f9f
tomcat-embed-core@9.0.37
9.0.81
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.