StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0

Open the chart page →

2,234
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,825
commonground-gateway-frontendcommonground-gateway-frontend0.1.01 of 1See more

commonground-gateway-frontend commonground-gateway-frontend 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,142
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,581
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0

Open the chart page →

1,544
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

12,915
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

5,959
consumer-helmconsumer-app-helm-chart0.1.01 of 1See more

consumer-helm consumer-app-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
j4ckhunter/consumer:1.00bb7a429e3e75
tomcat-embed-core@9.0.65
9.0.81

Open the chart page →

2,567
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,218
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

8,417
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.17.0

Open the chart page →

9,153
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.11 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

10,157
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

3,678
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
0.17.0
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

6,563
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

3,837
metacontrollercowboysysopVerified publisher1.2.21 of 1See more

metacontroller cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,092
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,577
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

2,582
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

5,489
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

2,275
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-zookeeper:6.1.078c190f4472c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

58,869
crashloop-operatorcrashloop-operator0.0.61 of 1See more

crashloop-operator crashloop-operator 0.0.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

505
logstream-mastercriblio2.9.91 of 1See more

logstream-master criblio 2.9.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cribl/cribl:3.0.2762747cb6796
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

9,296
bitwarden-rscronce0.1.71 of 1See more

bitwarden-rs cronce 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vaultwarden/server:1.27.0-alpine7cd450642c54
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,589
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

2,312
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,248
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

2,231
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0

Open the chart page →

4,631
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

5,980
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

5,980
pagescrypticcode-helmchart1.0.02 of 3See more

pages crypticcode-helmchart 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,349
openldapcsic-charts0.1.12 of 2See more

openldap csic-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
nghttp2@1.43.0-1
1.43.0-1+deb11u1
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0

Open the chart page →

5,294
rtcsic-charts0.1.13 of 5See more

rt csic-charts 0.1.1

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
nghttp2@1.51.0-r0
golang.org/x/net@v0.5.0
1.51.0-r2
0.17.0
firefart/requesttracker:5.0.40d6249906d8c
nghttp2@1.52.0-1
1.52.0-1+deb12u1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

15,419
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
nghttp2@1.40.0-1build1
golang.org/x/net@v0.5.0
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

13,944
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,239
cypikcypik-app0.1.01 of 2See more

cypik cypik-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
nginx@1.25.5-1~bookworm
no fix listed

Open the chart page →

7,548
irods-csi-drivercyverse0.12.02 of 4See more

irods-csi-driver cyverse 0.12.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

5,288
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

1,832
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

16,683
pagesdalston-pages1.0.02 of 3See more

pages dalston-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagesdaman-dell-kuber1.0.02 of 3See more

pages daman-dell-kuber 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0

Open the chart page →

3,246
cloudwatch-agent-prometheusdasmeta0.2.21 of 1See more

cloudwatch-agent-prometheus dasmeta 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0

Open the chart page →

2,985
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,806
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,933
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,768
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

18,881
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

22,445
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

24,375

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
refar/apm-operator-server:v5.7.1e5490f050f9f
tomcat-embed-core@9.0.37
9.0.81
1
remche/shinyproxy:2.6.18bcda8a04d3b
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
reportportal/migrations:5.7.0da5d8e1395fe
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20190424112056-4829fb13d2c6
1.46.0-r2
0.17.0
1
reportportal/service-api:5.7.29df41f8fb320
tomcat-embed-core@9.0.37
9.0.81
1
reportportal/service-authorization:5.7.09e73114dbd15
tomcat-embed-core@9.0.37
9.0.81
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0
1
reportportal/service-jobs:5.7.2dc166c58485a
tomcat-embed-core@9.0.43
9.0.81
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
reportportal/service-ui:5.7.20a08784eb901
nghttp2@1.47.0-r0
1.47.0-r2
1
restic/restic:0.15.2579e4e6a4931
golang.org/x/net@v0.8.0
0.17.0
1
rezachalak/bzen-mongo:1.0.034f694325191
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
tomcat-embed-core@8.5.11
8.5.94
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
tomcat-embed-core@8.5.4
8.5.94
1
rm3l/dev-feed-api:latest9a7f732245a3
nghttp2@1.43.0-5.el9_2.1
tomcat-embed-core@9.0.68
0:1.43.0-5.el9_3.1
9.0.81
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.55
1.40.0-1ubuntu0.2
9.0.81
1
robmarkcole/deepstack-ui:latest410275726459
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
robotshop/rs-dispatch:latestde81f1d07b02
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
robotshop/rs-payment:latest774b52c6180d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
robotshop/rs-ratings:latest4899c686c249
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
robotshop/rs-shipping:latest89753ab48919
tomcat-embed-core@9.0.37
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
nginx@1.22.1-9+deb12u4
no fix listed
1
rodolpheche/wiremock:2.27.22328a9fce2bf
http2-common@9.4.30.v20200611
http2-server@9.4.30.v20200611
9.4.53
9.4.53
1
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
royalwang/sentinel-dashboard:1.8.4df99e2499f91
tomcat-embed-core@9.0.60
9.0.81
1
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
0.17.0
1
samarthya/spinnaker:v1.0ef06d81036af
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.17.0
1
santisbon/speedtest:latest8ee3a1697227
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
sarwansharma/minio:v359d1da9385d1
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0:1.33.0-4.el8_6.1
0.17.0
1
savepointsam/unbound:1.15.09b9e0c057d23
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
tomcat-embed-core@9.0.55
9.0.81
1
scrapinghub/splash:3.4.1a5f89bc84606
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
tomcat-embed-core@9.0.21
9.0.81
1
seafileltd/seafile-mc:9.0.106693911bcc40
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
seafileltd/seafile-mc:10.0.170628f29c663
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
seafileltd/seafile-mc:9.0.97ac833196f60
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
nghttp2@1.55.1-r0
golang.org/x/net@v0.7.0
1.57.0-r0
0.17.0
1
seataio/seata-server:latest703b5de7f1a6
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
seataio/seata-server:1.5.1ee1ed55f4144
tomcat-embed-core@9.0.55
9.0.81
1
seldonio/apife:0.2.7ba81b17f00eb
tomcat-embed-core@8.5.34
8.5.94
1
seldonio/apife:0.3.1eea0d3f578ca
tomcat-embed-core@8.5.34
8.5.94
1
seldonio/cluster-manager:0.2.729e362bb1ba2
tomcat-embed-core@8.5.34
8.5.94
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1
1
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
0.17.0
1
semitechnologies/weaviate:1.19.17a00d226f063
golang.org/x/net@v0.7.0
0.17.0
1
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.