StackRadar

CVE-2023-45288

High

Advisory

Published 3 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.920
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,156
of 17,790 indexed, latest versions
Container images
2,573
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 2,156 of 17,790 indexed charts deploy, on 2,573 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.2.0-3.el8_91
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+189 more0.23.01,908
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+123 more1.21.92,481
OSV records
DEBIAN-CVE-2023-45288RHSA-2024:2699GHSA-4v7x-pqxf-cx7mGO-2024-2687
Also known as
BIT-golang-2023-45288, RHSA-2024:4546

Charts affected

2,156 by stars
ChartLatestAffected imagesRadar Score
attestkeepattestkeepVerified publisher1.1.01 of 2See more

attestkeep attestkeep 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/postgres:16.4-alpine5660c2cbfea5
stdlib@go1.18.2
1.21.9

Open the chart page →

1,598
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.23.0
1.21.9

Open the chart page →

7,570
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.23.0
1.21.9

Open the chart page →

1,727
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.23.0
1.21.9

Open the chart page →

5,082
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.23.0
1.21.9

Open the chart page →

6,958
kubeslice-workeraveshaVerified publisher1.5.02 of 14See more

kubeslice-worker avesha 1.5.0

2 of the 14 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
0.23.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9

Open the chart page →

1,644
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.21.9

Open the chart page →

860
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.17.3
0.23.0
1.21.9

Open the chart page →

2,487
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.23.0
1.21.9

Open the chart page →

2,946
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.3
0.23.0
1.21.9
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.3
0.23.0
1.21.9

Open the chart page →

2,966
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.23.0
1.21.9

Open the chart page →

2,140
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.21.9

Open the chart page →

9,728
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.23.0
1.21.9

Open the chart page →

4,575
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.23.0
1.21.9

Open the chart page →

5,528
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.23.0
1.21.9
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.23.0
1.21.9

Open the chart page →

7,723
keptn-addonsazureorkestra0.1.04 of 4See more

keptn-addons azureorkestra 0.1.0

4 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.23.0
1.21.9
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.21.9
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.23.0
1.21.9
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.2
0.23.0
1.21.9

Open the chart page →

10,629
prometheusazureorkestra14.8.05 of 6See more

prometheus azureorkestra 14.8.0

5 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.21.9
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.21.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.23.0
1.21.9
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.23.0
1.21.9
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.23.0
1.21.9

Open the chart page →

9,669
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.21.9

Open the chart page →

3,037
ragflowbaboulinet0.1.12 of 5See more

ragflow baboulinet 0.1.1

2 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.21.9
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9

Open the chart page →

5,894
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.23.0
1.21.9

Open the chart page →

1,501
backlokto-operatorbacklokto0.0.11 of 1See more

backlokto-operator backlokto 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.23.0
1.21.9

Open the chart page →

694
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.23.0
1.21.9

Open the chart page →

8,417
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.23.0
1.21.9

Open the chart page →

7,352
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.23.0
1.21.9

Open the chart page →

2,078
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.23.0
1.21.9

Open the chart page →

8,029
mx-notifierbicarus-labs1.1.91 of 1See more

mx-notifier bicarus-labs 1.1.9

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.23.0
1.21.9

Open the chart page →

3,763
wg-access-serverbicarus-labs0.9.91 of 1See more

wg-access-server bicarus-labs 0.9.9

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.23.0
1.21.9

Open the chart page →

2,755
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.23.0
1.21.9

Open the chart page →

2,336
stackbitpokeVerified publisher0.12.46 of 6See more

stack bitpoke 0.12.4

6 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.23.0
1.21.9
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.23.0
1.21.9
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.21.9
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.23.0
1.21.9
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.2
0.23.0
1.21.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.23.0
1.21.9

Open the chart page →

9,898
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.23.0
1.21.9

Open the chart page →

1,123
baserowblackbird-cloudVerified publisher1.0.172 of 6See more

baserow blackbird-cloud 1.0.17

2 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.21.9
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.23.0
1.21.9

Open the chart page →

10,225
prometheus-domain-exporterblackbox-domain-exporter1.0.01 of 1See more

prometheus-domain-exporter blackbox-domain-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.23.0
1.21.9

Open the chart page →

1,408
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
blackducksoftware/bdba-pgupgrader:2026.6.35c97f3a3f8b7
stdlib@go1.18.2
1.21.9

Open the chart page →

9,667
firehoseblip-firehoseVerified publisher0.0.183 of 11See more

firehose blip-firehose 0.0.18

3 of the 11 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.23.0
1.21.9
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.23.0
1.21.9
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.23.0
1.21.9

Open the chart page →

13,517
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.21.9

Open the chart page →

15,302
jaegerbook-k8sinfra-v23.4.04 of 5See more

jaeger book-k8sinfra-v2 3.4.0

4 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.21.9
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9

Open the chart page →

19,311
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.23.0
1.21.9

Open the chart page →

8,339
kube-prometheus-stackbook-k8sinfra-v265.5.11 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

1 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.23.0
1.21.9

Open the chart page →

6,044
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.23.0
1.21.9
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.23.0
1.21.9

Open the chart page →

3,857
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.23.0
1.21.9

Open the chart page →

2,745
prometheusbook-k8sinfra-v226.0.11 of 6See more

prometheus book-k8sinfra-v2 26.0.1

1 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.23.0
1.21.9

Open the chart page →

5,312
pyroscopebook-k8sinfra-v21.10.01 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.21.9

Open the chart page →

3,257
redisbook-k8sinfra-v21.0.01 of 1See more

redis book-k8sinfra-v2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.21.9

Open the chart page →

1,731
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
stdlib@go1.21.3
1.21.9

Open the chart page →

1,867
butane-operatorbutane-operatorVerified publisher0.3.01 of 2See more

butane-operator butane-operator 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.23.0
1.21.9

Open the chart page →

1,403
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.23.0
1.21.9

Open the chart page →

2,374
accelerationbuttahtoastVerified publisher0.1.01 of 1See more

acceleration buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
goharbor/harbor-acceld:0.2.13451103a6c8d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9

Open the chart page →

1,408
fluobuttahtoastVerified publisher0.1.01 of 1See more

fluo buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.23.0
1.21.9

Open the chart page →

1,298
kubermatic-operatorbuttahtoastVerified publisher2.24.51 of 1See more

kubermatic-operator buttahtoast 2.24.5

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/net@v0.19.0
stdlib@go1.20.6
0.23.0
1.21.9

Open the chart page →

2,781
kubevirt-managerbuttahtoastVerified publisher0.1.31 of 1See more

kubevirt-manager buttahtoast 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9

Open the chart page →

1,497

Container images carrying it

2,573 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
kubegems/chatgpt-api:latestf3c492a938ad
stdlib@go1.19.3
1.21.9
1
kubegems/chatgpt-api-feishubot:latest7c93c84b2055
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.23.0
1.21.9
1
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.23.0
1.21.9
1
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.23.0
1
kubegems/kubectl:latestc3b4be9a54f5
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20
0.23.0
1.21.9
1
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.15
0.23.0
1.21.9
1
kubegems/mysql:8.0.33-debian-11-r019cb195b9a50
stdlib@go1.19.8
1.21.9
1
kubemod/kubemod:v0.19.11f8154f7e80c
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.18
0.23.0
1.21.9
1
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.23.0
1.21.9
1
kubemod/kubemod-crt:v1.3.0028347c9fa77
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.18.1
0.23.0
1.21.9
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14
0.23.0
1.21.9
1
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.23.0
1.21.9
1
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19
0.23.0
1.21.9
1
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.23.0
1.21.9
1
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/net@v0.22.0
0.23.0
1
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.23.0
1.21.9
1
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.23.0
1.21.9
1
kubesec/kubesec:v2.13.0c0f3b0673578
stdlib@go1.19.7
1.21.9
1
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.23.0
1.21.9
1
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.10
0.23.0
1.21.9
1
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.10
0.23.0
1.21.9
1
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.23.0
1.21.9
1
kubeshop/tracetest:v1.7.173d7e3a2db43
golang.org/x/net@v0.17.0
0.23.0
1
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.23.0
1.21.9
1
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.6
0.23.0
1.21.9
1
kubesphere/ks-extensions-museum:latest29681958f220
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.23.0
1.21.9
1
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.23.0
1.21.9
1
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.23.0
1.21.9
1
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.23.0
1.21.9
1
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.23.0
1.21.9
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.10
0.23.0
1.21.9
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.23.0
1.21.9
1
kubestar/event-exporter:latest656606941255
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.23.0
1.21.9
1
kubesuite/kubereport:latest0262424ee702
stdlib@go1.22.0
1.21.9
1
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.23.0
1.21.9
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9
1
kudobuilder/controller:v0.9.069072d979708
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13
0.23.0
1.21.9
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.23.0
1.21.9
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.23.0
1.21.9
1
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
0.23.0
1
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.23.0
1.21.9
1
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.5
0.23.0
1.21.9
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
1
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.21.9
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.23.0
1.21.9
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.23.0
1.21.9
1
layer5/meshery-consul:stable-latest25a4cc38abcd
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.23.0
1.21.9
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.23.0
1.21.9
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/net@v0.17.0
0.23.0
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/net@v0.19.0
0.23.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.