CVE-2023-45283
HighAdvisory
Published 8 Nov 2023In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.028
- 86th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,904
- of 17,797 indexed, latest versions
- Container images
- 2,218
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Insecure parsing of Windows paths with a \??\ prefix in path/filepath
Carried by container images the latest versions of 1,904 of 17,797 indexed charts deploy, on 2,218 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+113 more | 1.20.11, 1.20.12 | 2,218 |
- OSV records
- DEBIAN-CVE-2023-45283GO-2023-2185
- Also known as
- BIT-golang-2023-45283
Charts affected
1,904 by stars
Container images carrying it
2,218 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 874405536b3e | stdlib | 1.20.11 | 1 |
| library/ | fbc51bcf1ab0 | stdlib | 1.20.11 | 1 |
| library/ | 96d8a3f65a4f | stdlib | 1.20.11 | 1 |
| library/ | 1d148deae16a | stdlib | 1.20.11 | 1 |
| library/ | 3153fa63f546 | stdlib | 1.20.11 | 1 |
| library/ | afa5d5134900 | stdlib | 1.20.11 | 1 |
| library/ | d9a0fd8bdd15 | stdlib | 1.20.11 | 1 |
| library/ | 83f7bf209844 | stdlib | 1.20.11 | 1 |
| library/ | a10d46445d68 | stdlib | 1.20.11 | 1 |
| library/ | ba10ac9ba17a | stdlib | 1.20.11 | 1 |
| library/ | d7f5dd5f70e2 | stdlib | 1.20.11 | 1 |
| library/ | 7232f6388a4d | stdlib | 1.20.11 | 1 |
| library/ | 17a4f64e9cf5 | stdlib | 1.20.11 | 1 |
| library/ | 07e06f2e7ae9 | stdlib | 1.20.11 | 1 |
| library/ | 1c33370a599c | stdlib | 1.20.11 | 1 |
| library/ | 22edfe1c7834 | stdlib | 1.20.11 | 1 |
| library/ | 490f01279be1 | stdlib | 1.20.11 | 1 |
| library/ | 5b6a1eac15b8 | stdlib | 1.20.11 | 1 |
| library/ | 8a16204dc96c | stdlib | 1.20.11 | 1 |
| library/ | 9a48ac9f196f | stdlib | 1.20.11 | 1 |
| library/ | bfc25a68e113 | stdlib | 1.20.11 | 1 |
| library/ | e22328f4d714 | stdlib | 1.20.11 | 1 |
| library/ | fbb8456ebdb1 | stdlib | 1.20.11 | 1 |
| library/ | fcc7fcd7114a | stdlib | 1.20.11 | 1 |
| library/ | 0032d2ca20db | stdlib | 1.20.11 | 1 |
| library/ | 05678ae4e5e1 | stdlib | 1.20.11 | 1 |
| library/ | 3d0e6df9fd5b | stdlib | 1.20.11 | 1 |
| library/ | 50cae5081ab4 | stdlib | 1.20.11 | 1 |
| library/ | 646902910d6a | stdlib | 1.20.11 | 1 |
| library/ | 699d652ed674 | stdlib | 1.20.11 | 1 |
| library/ | 71a63fc2438e | stdlib | 1.20.11 | 1 |
| library/ | 7c81758cb295 | stdlib | 1.20.11 | 1 |
| library/ | ae1cf99fa7bf | stdlib | 1.20.11 | 1 |
| library/ | d23ec07162ca | stdlib | 1.20.11 | 1 |
| library/ | dca8d11fe467 | stdlib | 1.20.11 | 1 |
| library/ | 106d5197fd8e | stdlib | 1.20.11 | 1 |
| library/ | 3c1aab708f6e | stdlib | 1.20.11 | 1 |
| library/ | 92dc86967801 | stdlib | 1.20.11 | 1 |
| library/ | bf577825b52a | stdlib | 1.20.11 | 1 |
| library/ | ccb8f749bb5e | stdlib | 1.20.11 | 1 |
| library/ | d58ac93387f6 | stdlib | 1.20.11 | 1 |
| library/ | ccbe811b8575 | stdlib | 1.20.11 | 1 |
| library/ | d6c6ae7df4a0 | stdlib | 1.20.11 | 1 |
| library/ | f576cdc17cc3 | stdlib | 1.20.11 | 1 |
| library/ | 0ad6861379c9 | stdlib | 1.20.12 | 1 |
| library/ | ced93c701875 | stdlib | 1.20.11 | 1 |
| library/ | 03652c675ae1 | stdlib | 1.20.11 | 1 |
| library/ | 2d1e636f0778 | stdlib | 1.20.11 | 1 |
| library/ | 304ab8135187 | stdlib | 1.20.11 | 1 |
| library/ | 557fea37a744 | stdlib | 1.20.11 | 1 |