StackRadar

CVE-2023-45288

High

Advisory

Published 3 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.920
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,255
of 17,828 indexed, latest versions
Container images
2,656
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 2,255 of 17,828 indexed charts deploy, on 2,656 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.2.0-3.el8_91
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+191 more0.23.01,973
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+125 more1.21.92,562
OSV records
DEBIAN-CVE-2023-45288RHSA-2024:2699GHSA-4v7x-pqxf-cx7mGO-2024-2687
Also known as
BIT-golang-2023-45288, RHSA-2024:4546

Charts affected

2,255 by stars
ChartLatestAffected imagesRadar Score
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.23.0
1.21.9
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.23.0
1.21.9
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.23.0
1.21.9
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.23.0
1.21.9

Open the chart page →

7,803
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.21.9

Open the chart page →

1,818
ghostcloudpirates-ghostVerified publisher0.20.251 of 3See more

ghost cloudpirates-ghost 0.20.25

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.21.9

Open the chart page →

7,086
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
stdlib@go1.18
0.23.0
1.21.9

Open the chart page →

1,708
coder-observabilitycoder-observabilityVerified publisher0.7.37 of 21See more

coder-observability coder-observability 0.7.3

7 of the 21 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.23.0
1.21.9
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.23.0
1.21.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.21.9
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.23.0
1.21.9
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.23.0
1.21.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.23.0
1.21.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.23.0
1.21.9

Open the chart page →

24,977
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.23.0
1.21.9

Open the chart page →

17,204
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.23.0
1.21.9

Open the chart page →

3,089
cosmocosmo-platformOfficialVerified publisher0.20.02 of 10See more

cosmo cosmo-platform 0.20.0

2 of the 10 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stdlib@go1.20.7
1.21.9
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.21.9

Open the chart page →

29,743
deepflowdeepflow6.2.2015 of 8See more

deepflow deepflow 6.2.201

5 of the 8 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.21.9
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.23.0
1.21.9
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.23.0
1.21.9
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.21.9
grafana/grafana:9.3.6e5a9655dabef
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.23.0
1.21.9

Open the chart page →

16,073
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
0.23.0

Open the chart page →

3,482
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9

Open the chart page →

1,624
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.23.0
1.21.9

Open the chart page →

2,538
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.21.9

Open the chart page →

1,277
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.23.0
1.21.9

Open the chart page →

2,273
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.23.0
1.21.9

Open the chart page →

12,055
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.23.0
1.21.9

Open the chart page →

14,559
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.23.0
1.21.9

Open the chart page →

13,888
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.21.9

Open the chart page →

5,344
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.7
0.23.0
1.21.9

Open the chart page →

3,037
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.21.9

Open the chart page →

1,111
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.23.0
1.21.9

Open the chart page →

1,746
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.10
0.23.0
1.21.9

Open the chart page →

7,638
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.21.9
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.23.0
1.21.9

Open the chart page →

4,766
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.21.9

Open the chart page →

9,872
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.23.0
1.21.9

Open the chart page →

10,330
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.4
0.23.0
1.21.9

Open the chart page →

2,338
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.23.0
1.21.9

Open the chart page →

3,379
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.17
0.23.0
1.21.9

Open the chart page →

2,612
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.21.9

Open the chart page →

10,899
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.23.0
1.21.9

Open the chart page →

2,235
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.21.9

Open the chart page →

12,022
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.21.9

Open the chart page →

6,710
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.23.0
1.21.9

Open the chart page →

1,655
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.2
0.23.0
1.21.9

Open the chart page →

1,559
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.5
0.23.0
1.21.9

Open the chart page →

2,624
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.23.0
1.21.9
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.23.0
1.21.9
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.21.9

Open the chart page →

31,052
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.23.0
1.21.9

Open the chart page →

2,212
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.21.9

Open the chart page →

4,710
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.21.9

Open the chart page →

7,566
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.21.9

Open the chart page →

1,607
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.21.9

Open the chart page →

2,310
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.23.0
1.21.9

Open the chart page →

1,566
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.23.0
1.21.9

Open the chart page →

1,621
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.23.0
1.21.9
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.23.0
1.21.9

Open the chart page →

18,056
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.23.0
1.21.9
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.21.9
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.21.9

Open the chart page →

14,254
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.04 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

4 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.23.0
1.21.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.23.0
1.21.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.23.0
1.21.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.23.0
1.21.9

Open the chart page →

56,636
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
0.23.0
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.23.0
1.21.9

Open the chart page →

3,327
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.23.0
1.21.9

Open the chart page →

3,694
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.23.0
1.21.9
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.23.0
1.21.9
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.23.0
1.21.9

Open the chart page →

5,612
lumigo-operatorlumigo-operatorOfficialVerified publisher69.0.01 of 8See more

lumigo-operator lumigo-operator 69.0.0

1 of the 8 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
public.ecr.aws/lumigo/lumigo-kubernetes-rbac-proxy:696c2f0585cd6c
golang.org/x/net@v0.10.0
0.23.0

Open the chart page →

7,797

Container images carrying it

2,656 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.23.0
1.21.9
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
stdlib@go1.20.7
0.23.0
1.21.9
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.23.0
1.21.9
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/net@v0.17.0
0.23.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.23.0
1.21.9
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.23.0
1.21.9
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
stdlib@go1.20.6
1.21.9
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
stdlib@go1.20.10
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.2
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/net@v0.10.0
stdlib@go1.20.1
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
golang.org/x/net@v0.8.0
stdlib@go1.20.1
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/net@v0.22.0
0.23.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/net@v0.21.0
stdlib@go1.21.6
0.23.0
1.21.9
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.23.0
1.21.9
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.23.0
1.21.9
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.23.0
1.21.9
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.23.0
1.21.9
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9
1
registry.k8s.io/kube-scheduler:v1.23.143e149d206076
stdlib@go1.17.13
1.21.9
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.23.0
1.21.9
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.23.0
1.21.9
1
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.23.0
1.21.9
1
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.23.0
1.21.9
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
stdlib@go1.18
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/net@v0.4.0
stdlib@go1.19
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.18
0.23.0
1.21.9
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
stdlib@go1.19
0.23.0
1.21.9
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.