StackRadar

CVE-2023-45288

High

Advisory

Published 3 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.920
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,154
of 17,797 indexed, latest versions
Container images
2,571
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 2,154 of 17,797 indexed charts deploy, on 2,571 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.2.0-3.el8_91
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+189 more0.23.01,907
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+123 more1.21.92,479
OSV records
DEBIAN-CVE-2023-45288RHSA-2024:2699GHSA-4v7x-pqxf-cx7mGO-2024-2687
Also known as
BIT-golang-2023-45288, RHSA-2024:4546

Charts affected

2,154 by stars
ChartLatestAffected imagesRadar Score
harborkubesphereVerified publisher1.9.37 of 11See more

harbor kubesphere 1.9.3

7 of the 11 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
stdlib@go1.17.7
0.23.0
1.21.9
goharbor/harbor-core:v2.5.386bf3031f4a7
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.23.0
1.21.9
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.23.0
1.21.9
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.23.0
1.21.9
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.23.0
1.21.9
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.23.0
1.21.9
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.18.3
0.23.0
1.21.9

Open the chart page →

17,853
pvc-autoresizerkubesphereVerified publisher0.1.01 of 1See more

pvc-autoresizer kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.10
0.23.0
1.21.9

Open the chart page →

1,563
storageclass-accessorkubesphereVerified publisher0.1.01 of 1See more

storageclass-accessor kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.23.0
1.21.9

Open the chart page →

1,510
ccm-qingcloudkubesphere-stable0.1.01 of 1See more

ccm-qingcloud kubesphere-stable 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.21.9

Open the chart page →

1,540
chaos-meshkubesphere-stable2.5.13 of 3See more

chaos-mesh kubesphere-stable 2.5.1

3 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.23.0
1.21.9
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.23.0
1.21.9
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.23.0
1.21.9

Open the chart page →

8,582
cni-hostnickubesphere-stable0.1.01 of 1See more

cni-hostnic kubesphere-stable 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.23.0
1.21.9

Open the chart page →

2,444
cranekubesphere-stable0.5.23 of 3See more

crane kubesphere-stable 0.5.2

3 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
gocrane/crane-scheduler:0.0.239ba6d11b2079
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.2
0.23.0
1.21.9
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.2
0.23.0
1.21.9
gocrane/craned:v0.5.1a1400909118c
stdlib@go1.17.2
1.21.9

Open the chart page →

8,903
csi-qingcloudkubesphere-stable1.4.06 of 6See more

csi-qingcloud kubesphere-stable 1.4.0

6 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.23.0
1.21.9
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.23.0
1.21.9

Open the chart page →

12,446
curvefs-csikubesphere-stable0.1.01 of 3See more

curvefs-csi kubesphere-stable 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.23.0
1.21.9

Open the chart page →

2,831
deepflowkubesphere-stable6.2.6065 of 8See more

deepflow kubesphere-stable 6.2.606

5 of the 8 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.21.9
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.23.0
1.21.9
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
stdlib@go1.19.1
0.23.0
1.21.9
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.21.9
grafana/grafana:9.5.239c849cebccc
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.23.0
1.21.9

Open the chart page →

18,435
edgemeshkubesphere-stable0.1.02 of 2See more

edgemesh kubesphere-stable 0.1.0

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.23.0
1.21.9
kubeedge/edgemesh-server:latesta437cf5ec0ae
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.11
0.23.0
1.21.9

Open the chart page →

4,108
fpga-operatorkubesphere-stable2.7.43 of 7See more

fpga-operator kubesphere-stable 2.7.4

3 of the 7 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.23.0
1.21.9
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.21.9
inaccel/reef:latestc967218739f3
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.23.0
1.21.9

Open the chart page →

5,771
iomeshkubesphere-stable1.1.023 of 25See more

iomesh kubesphere-stable 1.1.0

23 of the 25 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.20.3
0.23.0
1.21.9
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.20.3
0.23.0
1.21.9
iomesh/csi-driver:v2.7.25d3f9bf9240b
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.7
0.23.0
1.21.9
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.23.0
1.21.9
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.23.0
1.21.9
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/net@v0.8.0
stdlib@go1.19
0.23.0
1.21.9
iomesh/deck:v0.1.0a31e26b6ae22
golang.org/x/net@v0.17.0
0.23.0
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
golang.org/x/net@v0.19.0
0.23.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.1
0.23.0
1.21.9
iomesh/livenessprobe:v2.8.0560f01510f99
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.23.0
1.21.9
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.23.0
1.21.9
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.23.0
1.21.9
iomesh/node-disk-manager:1.8.0002c4b92fd34
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.23.0
1.21.9
iomesh/node-disk-operator:1.8.0f6c76380db34
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.23.0
1.21.9
iomesh/operator:v1.1.060081c9b2f52
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.23.0
1.21.9
iomesh/post-delete-hook:v1.1.0eea5651f3270
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.23.0
1.21.9
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/net@v0.8.0
stdlib@go1.19
0.23.0
1.21.9
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9

Open the chart page →

49,004
IOMeshkubesphere-stable1.2.023 of 25See more

IOMesh kubesphere-stable 1.2.0

23 of the 25 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.5
0.23.0
1.21.9
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.5
0.23.0
1.21.9
iomesh/csi-driver:v2.8.01a151f602451
golang.org/x/net@v0.8.0
0.23.0
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.23.0
1.21.9
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.23.0
1.21.9
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/net@v0.8.0
stdlib@go1.19
0.23.0
1.21.9
iomesh/deck:v0.2.0282d6c419ed3
golang.org/x/net@v0.19.0
0.23.0
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
golang.org/x/net@v0.19.0
0.23.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.1
0.23.0
1.21.9
iomesh/livenessprobe:v2.8.0560f01510f99
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.23.0
1.21.9
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.23.0
1.21.9
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.23.0
1.21.9
iomesh/node-disk-manager:1.8.0-2292ad270082e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.23.0
1.21.9
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.23.0
1.21.9
iomesh/operator:v1.2.0ba4dd6be7e59
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.23.0
1.21.9
iomesh/post-delete-hook:v1.2.0e3b92f838f4b
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.23.0
1.21.9
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/net@v0.8.0
stdlib@go1.19
0.23.0
1.21.9
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9

Open the chart page →

46,692
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.13.10
0.23.0
1.21.9
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.6
0.23.0
1.21.9

Open the chart page →

14,457
aws-fsx-csi-driverkubesphere-testVerified publisher0.1.01 of 4See more

aws-fsx-csi-driver kubesphere-test 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.23.0
1.21.9

Open the chart page →

1,595
ccm-qingcloudkubesphere-testVerified publisher0.1.01 of 1See more

ccm-qingcloud kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.21.9

Open the chart page →

1,540
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.23.0
1.21.9

Open the chart page →

2,444
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.23.0
1.21.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.23.0
1.21.9

Open the chart page →

18,537
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.23.0
1.21.9
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.23.0
1.21.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.23.0
1.21.9

Open the chart page →

12,446
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.23.0
1.21.9

Open the chart page →

2,831
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.21.9

Open the chart page →

9,640
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.23.0
1.21.9
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.23.0
1.21.9

Open the chart page →

26,079
openelbkubesphere-testVerified publisher0.2.42 of 2See more

openelb kubesphere-test 0.2.4

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.23.0
1.21.9
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.23.0
1.21.9

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.23.0
1.21.9

Open the chart page →

2,791
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.23.0
1.21.9

Open the chart page →

2,220
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
golang.org/x/net@v0.19.0
stdlib@go1.20.4
0.23.0
1.21.9

Open the chart page →

4,458
kubestellar-uikubestellaruiVerified publisher0.1.12 of 4See more

kubestellar-ui kubestellarui 0.1.1

2 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.21.9
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9

Open the chart page →

4,778
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.21.9

Open the chart page →

8,795
kube-workload-restarterkube-workload-restarterVerified publisher0.0.41 of 1See more

kube-workload-restarter kube-workload-restarter 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.23.0
1.21.9

Open the chart page →

1,815
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.21.9
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.23.0
1.21.9

Open the chart page →

20,435
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.23.0
1.21.9

Open the chart page →

3,477
operatingkusionstackVerified publisher0.5.11 of 1See more

operating kusionstack 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.23.0
1.21.9

Open the chart page →

1,881
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.23.0
1.21.9

Open the chart page →

2,511
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.23.0
1.21.9

Open the chart page →

16,561
metadockvalitetsitVerified publisher0.0.72 of 2See more

metadoc kvalitetsit 0.0.7

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.5
0.23.0
1.21.9
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9

Open the chart page →

4,033
nsp-prometheus-exporterkvalitetsitVerified publisher1.0.191 of 2See more

nsp-prometheus-exporter kvalitetsit 1.0.19

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.21.9

Open the chart page →

2,064
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.23.0
1.21.9

Open the chart page →

7,857
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.23.0
1.21.9

Open the chart page →

8,544
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
golang.org/x/net@v0.21.0
0.23.0

Open the chart page →

5,333
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14
0.23.0
1.21.9

Open the chart page →

26,400
lagoon-docker-hostlagoon-chartsVerified publisher0.7.01 of 1See more

lagoon-docker-host lagoon-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
stdlib@go1.21.3
1.21.9

Open the chart page →

2,125
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
stdlib@go1.20.14
1.21.9

Open the chart page →

1,385
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.21.9

Open the chart page →

33,613
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.23.0
1.21.9
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.23.0
1.21.9

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.55 of 6See more

prometheus lectures-k8sinfra 15.8.5

5 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.21.9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.23.0
1.21.9
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.23.0
1.21.9
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.23.0
1.21.9
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.4
0.23.0
1.21.9

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.23.0
1.21.9

Open the chart page →

3,198
prometheusleechistest11.6.04 of 6See more

prometheus leechistest 11.6.0

4 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.23.0
1.21.9
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.23.0
1.21.9
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.21.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.23.0
1.21.9

Open the chart page →

8,492
kube-benchlemontechVerified publisher0.1.01 of 1See more

kube-bench lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.21.9

Open the chart page →

1,632
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.23.0
1.21.9

Open the chart page →

4,280

Container images carrying it

2,571 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.21.9
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.21.9
1
pannoi/kollektor:1.0.59559617788fc
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.23.0
1.21.9
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.21.9
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.21.9
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9
1
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
stdlib@go1.21.5
0.23.0
1.21.9
1
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/net@v0.10.0
stdlib@go1.19.3
0.23.0
1.21.9
1
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.18.5
0.23.0
1.21.9
1
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.21.9
1
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.23.0
1.21.9
1
phntom/goalert:0.0.298ca4df55499b
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.23.0
1.21.9
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.16.2
0.23.0
1.21.9
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
stdlib@go1.19.2
0.23.0
1.21.9
1
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.23.0
1.21.9
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.3
0.23.0
1.21.9
1
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.23.0
1.21.9
1
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.23.0
1.21.9
1
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.23.0
1.21.9
1
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.23.0
1.21.9
1
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.23.0
1.21.9
1
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.23.0
1.21.9
1
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.23.0
1.21.9
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.21.9
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.12
0.23.0
1.21.9
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.21.9
1
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
golang.org/x/net@v0.7.0
0.23.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.23.0
1.21.9
1
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/net@v0.17.0
stdlib@go1.20.13
0.23.0
1.21.9
1
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
stdlib@go1.20.3
0.23.0
1.21.9
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.23.0
1.21.9
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.21.9
1
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.21.9
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.12
0.23.0
1.21.9
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.23.0
1.21.9
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.23.0
1.21.9
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.21.9
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.19.3
0.23.0
1.21.9
1
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/net@v0.0.0-20220728211354-c7608f3a8462
stdlib@go1.18.5
0.23.0
1.21.9
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.23.0
1.21.9
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.21.9
1
prom/influxdb-exporter:v0.11.427e33e18634a
stdlib@go1.19.9
1.21.9
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.21.9
1
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.2
0.23.0
1.21.9
1
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.23.0
1.21.9
1
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/net@v0.22.0
0.23.0
1
prom/prometheus:v2.18.15880ec936055
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.14.2
0.23.0
1.21.9
1
prom/prometheus:v2.48.0b440bc0e8aa5
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.23.0
1.21.9
1
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.23.0
1.21.9
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.