StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,181
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,826
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,812
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,267
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,234
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,542
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,542
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
tomcat-embed-core@9.0.29
9.0.81

Open the chart page →

12,516
blockscoutethereum-helm-chartsVerified publisher0.2.31 of 2See more

blockscout ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
blockscout/blockscout:5.1.5c365a8f2dc12
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,928
chaos-meshethereum-helm-chartsVerified publisher0.0.31 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

12,202
dugtrioethereum-helm-chartsVerified publisher0.0.71 of 1See more

dugtrio ethereum-helm-charts 0.0.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ethpandaops/dugtrio:1.0.0e261d1734e9f
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,145
forkmonethereum-helm-chartsVerified publisher0.1.61 of 1See more

forkmon ethereum-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
holiman/nodemonitor:latest5cd609761065
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

1,694
powfaucetethereum-helm-chartsVerified publisher1.2.11 of 1See more

powfaucet ethereum-helm-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pk910/powfaucet:v2-stable3dcae6a62896
nginx@1.27.5-1~bookworm
no fix listed

Open the chart page →

4,479
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,688
ethexporterethersphereVerified publisher0.3.01 of 1See more

ethexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
darkobas/ethexporter:latest62e6464491ba
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,394
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.186d6d12a40465
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0

Open the chart page →

4,756
tokenexporterethersphereVerified publisher0.3.01 of 1See more

tokenexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
darkobas/tokenexporter:latesta0349a0eedf0
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,394
nist-data-mirroreugen0.1.21 of 1See more

nist-data-mirror eugen 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,958
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

20,983
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

6,041
exa-csiexa-csi-driver0.2.0-rev22 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0

Open the chart page →

7,091
faasnetfaasnet0.0.42 of 5See more

faasnet faasnet 0.0.4

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.17.0
simpleidserver/faaswebsite:0.0.4367218ae760f
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,704
degafactlyVerified publisher0.11.131 of 3See more

dega factly 0.11.13

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
factly/dega-server:0.15.194d21479382e
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

5,747
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

4,086
kavachfactlyVerified publisher0.9.51 of 2See more

kavach factly 0.9.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

3,573
mandefactlyVerified publisher0.5.162 of 3See more

mande factly 0.5.16

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
golang.org/x/net@v0.7.0
0.17.0
factly/mande-studio:0.34.19db4bee30e63
nghttp2@1.51.0-r1
1.51.0-r2

Open the chart page →

4,785
basic-demofairwinds-incubator1.0.01 of 1See more

basic-demo fairwinds-incubator 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
nghttp2@1.53.0-r0
1.57.0-r0

Open the chart page →

1,599
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

4,647
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

1,743
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

1,765
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

4,127
activityrelayfedihost0.1.42 of 2See more

activityrelay fedihost 0.1.4

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stratospire/activityrelay:0.2.3a4c34cb01117
nghttp2@1.43.0-1
1.43.0-1+deb11u1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

13,502
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

7,523
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
0.17.0

Open the chart page →

14,692
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,318
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
tomcat-embed-core@9.0.53
9.0.81

Open the chart page →

7,696
first-matefirst-mateVerified publisher1.0.51 of 1See more

first-mate first-mate 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chriswells0/first-mate:1.0.5f3918ec8471c
nghttp2@1.53.0-r0
golang.org/x/net@v0.8.0
1.57.0-r0
0.17.0

Open the chart page →

1,722
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

6,936
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

8,528
dsba-pdpfiware0.1.21 of 2See more

dsba-pdp fiware 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

4,105
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.43 of 4See more

endpoint-auth-service fiware 0.1.4

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

11,836
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,778
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

7,019
orionfiware1.6.111 of 2See more

orion fiware 1.6.11

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1

Open the chart page →

10,638
scorpio-brokerfiware0.3.310 of 10See more

scorpio-broker fiware 0.3.3

10 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
tomcat-embed-core@9.0.26
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
tomcat-embed-core@9.0.55
9.0.81

Open the chart page →

55,629
scorpiobrokerfiware0.1.210 of 10See more

scorpiobroker fiware 0.1.2

10 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
tomcat-embed-core@9.0.26
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
tomcat-embed-core@9.0.55
9.0.81
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
tomcat-embed-core@9.0.55
9.0.81

Open the chart page →

55,629
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
tomcat-embed-core@9.0.55
9.0.81

Open the chart page →

5,289
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

7,087
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.17.0

Open the chart page →

3,372

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nghttp2@1.43.0-5.el9
nginx@1:1.20.1-13.el9
0:1.43.0-5.el9_2.1
1:1.22.1-5.module+el9.3.0.z+20438+032561a0
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
1.30.0-1ubuntu1+esm2
0.17.0
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.17.0
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
nghttp2@1.51.0-r0
1.51.0-r2
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.17.0
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.40.0-1ubuntu0.2
0.17.0
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
http2-common@9.4.34.v20201102
nghttp2@1.43.0-1
9.4.53
1.43.0-1+deb11u1
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.0.0-20181017193950-04a2e542c03f
0.17.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
0.17.0
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
0.17.0
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/net@v0.12.0
0.17.0
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
0.17.0
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.17.0
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nginx@1.29.1-1~bookworm
no fix listed
1
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-3.el8_2.2
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/k10app/businit:latest94c9a3e799c2
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.51.0-r2
0.17.0
1
ghcr.io/k10app/frontend:latest066b5ac6b119
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.