StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

5,047
zahori-moonzahoriVerified publisher1.0.13 of 3See more

zahori-moon zahori 1.0.1

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,907
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.14

Open the chart page →

3,487
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.81

Open the chart page →

5,852
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,697

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
0.17.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
0.17.0
2
cs3org/wopiserver:v9.4.202a9e78757b4
nghttp2@1.51.0-r0
1.51.0-r2
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0
2
daniacobext/airports-frontend:latest9eae4d39fc33
nghttp2@1.51.0-r0
1.51.0-r2
2
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
2
dependencytrack/frontend:4.6.124422d762e08
nghttp2@1.47.0-r0
1.47.0-r2
2
devopsjourney1/mywebapp:latestbd1ec6838570
nghttp2@1.47.0-r0
1.47.0-r2
2
dina1993/airports-api:latestac731244aed1
tomcat-embed-core@10.1.7
10.1.14
2
dina1993/airports-consumer:latest669d146a5e63
tomcat-embed-core@10.1.7
10.1.14
2
dina1993/airports-producer:latest3d6b0dac1cb4
tomcat-embed-core@10.1.7
10.1.14
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
1.47.0-r2
0.17.0
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.37
1.40.0-1ubuntu0.2
9.0.81
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.37
1.40.0-1ubuntu0.2
9.0.81
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.37
1.40.0-1ubuntu0.2
9.0.81
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.37
1.40.0-1ubuntu0.2
9.0.81
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.37
1.40.0-1ubuntu0.2
9.0.81
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
1.52.0-1+deb12u1
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.17.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
2
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
0.17.0
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
2
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
2
hashicorp/consul:1.14.2e38576edcdfd
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.46.0-r2
0.17.0
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
2
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
2
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
0.17.0
2
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
2
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
2
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
0.17.0
2
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
2
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
2
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/net@v0.8.0
0.17.0
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.17.0
2
iomesh/livenessprobe:v2.8.0560f01510f99
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.17.0
2
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
2
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.