StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,191
of 17,828 indexed, latest versions
Container images
2,543
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,191 of 17,828 indexed charts deploy, on 2,543 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more575
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0217
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+8 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more182
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r0, 1.22.0-r1, 1.22.1-r0+2 more1.20.2-r2, 1.22.1-r1, 1.24.0-r714
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,614
tomcat-embed-coremaven8.5.4, 8.5.6, 8.5.11, 8.5.14+52 more8.5.94, 9.0.81, 10.1.14166
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+11 more9.4.53, 11.0.1721
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1717
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.47+8 more8.5.94, 9.0.8113
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,191 by stars
ChartLatestAffected imagesRadar Score
kingkfirfer0.1.01 of 1See more

king kfirfer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfirfer/king:latestc05d9fc7ae77
nghttp2@1.51.0-r1
1.51.0-r2

Open the chart page →

1,173
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

864
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

10,343
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

2,321
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/promtail:2.6.1072527b12cdf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
istio/pilot:1.15.2db08d6963975
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
1.43.0-1ubuntu0.1
0.17.0
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
0.17.0
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

19,289
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,971
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

3,186
kubeflowkromanow94-kubeflow0.5.14 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

4 of the 30 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/net@v0.13.0
0.17.0
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

71,477
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.39
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

8,938
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0

Open the chart page →

2,112
astralkronkltdVerified publisher0.1.01 of 1See more

astral kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
duck1123/astral:latestf4d5b6526c2a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

891
cloudbeaverkronkltdVerified publisher0.6.01 of 1See more

cloudbeaver kronkltd 0.6.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:21.3.00c0985098263
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,092
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

3,792
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.17.0
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
0.17.0
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.17.0

Open the chart page →

8,475
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

5,671
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.51.0-r2
0.17.0

Open the chart page →

3,650
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
1.46.0-r2
0.17.0

Open the chart page →

2,321
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
nginx@1.20.2-r0
1.20.2-r2

Open the chart page →

4,256
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.17.0

Open the chart page →

3,820
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,948
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,948
chartmuseumkubebb3.10.21 of 1See more

chartmuseum kubebb 3.10.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,277
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0

Open the chart page →

8,179
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,997
hello-worldkubebb0.1.11 of 1See more

hello-world kubebb 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/hello-world:0.1.0b746824819f3
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,225
ingress-nginxkubebb4.7.02 of 2See more

ingress-nginx kubebb 4.7.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

3,100
kubebb-corekubebb0.1.271 of 1See more

kubebb-core kubebb 0.1.27

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

1,948
miniokubebb5.0.102 of 2See more

minio kubebb 5.0.10

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.4.0
0:1.33.0-5.el8_8
0.17.0
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

7,614
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
tomcat-embed-core@9.0.65
9.0.81

Open the chart page →

4,668
tapm-componentkubebb5.7.12 of 3See more

tapm-component kubebb 5.7.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
tomcat-embed-core@9.0.37
9.0.81
refar/apm-operator-server:v5.7.1e5490f050f9f
tomcat-embed-core@9.0.37
9.0.81

Open the chart page →

10,259
tdsfkubebb5.7.02 of 3See more

tdsf kubebb 5.7.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
tomcat-embed-core@10.1.12
10.1.14
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

6,504
tekton-operatorkubebb0.64.02 of 2See more

tekton-operator kubebb 0.64.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

2,434
u4a-componentkubebb0.2.106 of 8See more

u4a-component kubebb 0.2.10

6 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

13,856
weaviatekubebb16.3.01 of 1See more

weaviate kubebb 16.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
semitechnologies/weaviate:1.19.17a00d226f063
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,876
chaos-meshkubeblocksVerified publisher2.7.21 of 4See more

chaos-mesh kubeblocks 2.7.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

13,686
dt-platformkubeblocksVerified publisher0.1.21 of 1See more

dt-platform kubeblocks 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

880
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
nghttp2@1.55.1-r0
golang.org/x/net@v0.12.0
1.57.0-r0
0.17.0

Open the chart page →

3,581
jupyterhubkubeblocksVerified publisher0.1.03 of 7See more

jupyterhub kubeblocks 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
nghttp2@1.55.1-r0
1.57.0-r0
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
nghttp2@1.43.0-1
1.43.0-1+deb11u1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,431
kubeblocks-csi-driverkubeblocksVerified publisher0.1.31 of 6See more

kubeblocks-csi-driver kubeblocks 0.1.3

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

2,090
kubetrankubeblocksVerified publisher0.1.01 of 1See more

kubetran kubeblocks 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,208
lokikubeblocksVerified publisher5.39.02 of 5See more

loki kubeblocks 5.39.0

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
0.17.0
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
nginx@1.24.0-r1
1.24.0-r7

Open the chart page →

5,864
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

4,524
openebskubeblocksVerified publisher3.10.02 of 3See more

openebs kubeblocks 3.10.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

10,633
prometheuskubeblocksVerified publisher15.16.15 of 6See more

prometheus kubeblocks 15.16.1

5 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
quay.io/prometheus/prometheus:v2.39.14748e26f9369
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

10,325
smartfs-csi-driverkubeblocksVerified publisher0.1.21 of 6See more

smartfs-csi-driver kubeblocks 0.1.2

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

9,260
snapshot-controllerkubeblocksVerified publisher1.7.21 of 1See more

snapshot-controller kubeblocks 1.7.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

1,128
victoria-metrics-alertkubeblocksVerified publisher0.8.3-reload1 of 3See more

victoria-metrics-alert kubeblocks 0.8.3-reload

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

3,717
kubeclaritykubeclarity2.23.32 of 5See more

kubeclarity kubeclarity 2.23.3

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:7.87.0f7f265d5c64e
nghttp2@1.47.0-r0
1.47.0-r2
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

5,522
cephfs-csikubegems1.0.81 of 6See more

cephfs-csi kubegems 1.0.8

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0

Open the chart page →

4,454
chartmuseumkubegems3.8.01 of 1See more

chartmuseum kubegems 3.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
0.17.0

Open the chart page →

3,527

Container images carrying it

2,543 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
0.17.0
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0:1.33.0-5.el8_8
0.17.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.17.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
nghttp2@1.51.0-r0
golang.org/x/net@v0.5.0
1.51.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
0.17.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.17.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.17.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/net@v0.13.0
0.17.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.