StackRadar

CVE-2023-45288

High

Advisory

Published 3 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.920
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,153
of 17,790 indexed, latest versions
Container images
2,569
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 2,153 of 17,790 indexed charts deploy, on 2,569 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.2.0-3.el8_91
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+189 more0.23.01,905
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+123 more1.21.92,477
OSV records
DEBIAN-CVE-2023-45288RHSA-2024:2699GHSA-4v7x-pqxf-cx7mGO-2024-2687
Also known as
BIT-golang-2023-45288, RHSA-2024:4546

Charts affected

2,153 by stars
ChartLatestAffected imagesRadar Score
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.23.0
1.21.9

Open the chart page →

3,023
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.23.0
1.21.9

Open the chart page →

3,313
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
stdlib@go1.18.1
1.21.9

Open the chart page →

3,466
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.3
0.23.0
1.21.9

Open the chart page →

2,330
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.23.0
1.21.9

Open the chart page →

3,313
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.23.0
1.21.9
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.21.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.23.0
1.21.9
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.23.0
1.21.9

Open the chart page →

9,754
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
golang.org/x/net@v0.6.0
stdlib@go1.19.4
0.23.0
1.21.9

Open the chart page →

4,570
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
stdlib@go1.21.6
1.21.9
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.23.0
1.21.9

Open the chart page →

4,883
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.21.9

Open the chart page →

2,637
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.81 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.23.0
1.21.9

Open the chart page →

2,092
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.21.9

Open the chart page →

5,499
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.8
0.23.0
1.21.9

Open the chart page →

2,213
secret-syncsecret-syncVerified publisher0.1.111 of 1See more

secret-sync secret-sync 0.1.11

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.23.0
1.21.9

Open the chart page →

1,442
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.23.0
1.21.9

Open the chart page →

2,407
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.21.9

Open the chart page →

922
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.23.0
1.21.9
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.23.0
1.21.9
prom/prometheus:v2.18.15880ec936055
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.14.2
0.23.0
1.21.9
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.21.9

Open the chart page →

10,733
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.23.0
1.21.9

Open the chart page →

3,336
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/net@v0.12.0
stdlib@go1.19.11
0.23.0
1.21.9

Open the chart page →

4,203
service-binding-operatorservice-binding-operator-helm-chart1.4.11 of 1See more

service-binding-operator service-binding-operator-helm-chart 1.4.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/redhat-developer/servicebinding-operatordigest-pinned16286ac84ddd
golang.org/x/net@v0.17.0
stdlib@go1.20.6
0.23.0
1.21.9

Open the chart page →

796
serviceexampleserviceexample0.1.03 of 5See more

serviceexample serviceexample 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/nats:2.9.20-alpined6c6ae7df4a0
stdlib@go1.19.11
1.21.9
natsio/nats-box:0.13.559cf2e949181
stdlib@go1.19.5
1.21.9
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
stdlib@go1.20.5
1.21.9

Open the chart page →

5,449
service-exampleservice-example-10.1.04 of 7See more

service-example service-example-1 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/nats:2.9.11-alpineccbe811b8575
stdlib@go1.19.4
1.21.9
natsio/nats-box:0.13.3c507bd7e3831
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.23.0
1.21.9
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
stdlib@go1.19.4
1.21.9
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
stdlib@go1.19.3
1.21.9

Open the chart page →

9,074
ccx-monitoringseveralnines0.6.213 of 7See more

ccx-monitoring severalnines 0.6.21

3 of the 7 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
victoriametrics/vmalert:v1.96.0150cd08fde94
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.23.0
1.21.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.23.0
1.21.9

Open the chart page →

7,709
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.23.0
1.21.9

Open the chart page →

1,698
shopwareshopware-storeVerified publisher2.1.21See more

shopware shopware-store 2.1.2

1 container image this version deploys carries CVE-2023-45288.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9

Open the chart page →

backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.21.9
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.21.9

Open the chart page →

10,972
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.14
0.23.0
1.21.9

Open the chart page →

2,181
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.21.9

Open the chart page →

2,919
trilliansigstoreVerified publisher0.3.201 of 5See more

trillian sigstore 0.3.20

1 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.21.9

Open the chart page →

2,739
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
golang.org/x/net@v0.6.0
stdlib@go1.19.6
0.23.0
1.21.9

Open the chart page →

2,863
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
golang.org/x/net@v0.19.0
stdlib@go1.21.4
0.23.0
1.21.9

Open the chart page →

2,316
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.23.0
1.21.9

Open the chart page →

2,381
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.23.0
1.21.9

Open the chart page →

1,494
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.10
0.23.0
1.21.9

Open the chart page →

2,165
mimirskyloud-helm-chartsVerified publisher5.5.13 of 5See more

mimir skyloud-helm-charts 5.5.1

3 of the 5 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
grafana/rollout-operator:v0.14.03409edfb45c7
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.23.0
1.21.9
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.23.0
1.21.9
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.23.0
1.21.9

Open the chart page →

10,650
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.23.0
1.21.9

Open the chart page →

2,110
flux-notifierslamdev0.0.71 of 1See more

flux-notifier slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.21.9

Open the chart page →

2,015
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.9
0.23.0
1.21.9

Open the chart page →

9,235
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/net@v0.0.0-20200501053045-e0ff5e5a1de5
stdlib@go1.13.11
0.23.0
1.21.9

Open the chart page →

2,860
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15
0.23.0
1.21.9

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.23.0
1.21.9

Open the chart page →

8,697
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.21.9

Open the chart page →

4,376
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.21.9

Open the chart page →

4,376
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.2
0.23.0
1.21.9

Open the chart page →

3,462
smarter-device-managersmarter-device-manager0.0.101 of 1See more

smarter-device-manager smarter-device-manager 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.23.0
1.21.9

Open the chart page →

1,144
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
stdlib@go1.19.8
1.21.9

Open the chart page →

5,571
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.21.9

Open the chart page →

7,586
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
golang.org/x/net@v0.0.0-20220513224357-95641704303c
stdlib@go1.18.2
0.23.0
1.21.9

Open the chart page →

1,842
harborsoftonic1.13.05 of 8See more

harbor softonic 1.13.0

5 of the 8 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.23.0
1.21.9
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.23.0
1.21.9
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.23.0
1.21.9
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.21.9
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.23.0
1.21.9

Open the chart page →

7,672
hello-world-appsoftonic1.2.21 of 1See more

hello-world-app softonic 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.21.9

Open the chart page →

1,957
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-45288.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.9
0.23.0
1.21.9

Open the chart page →

2,561

Container images carrying it

2,569 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.21.9
22
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.21.9
14
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.23.0
1.21.9
13
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.21.9
11
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.21.9
10
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.23.0
1.21.9
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.23.0
1.21.9
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.23.0
1.21.9
8
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.23.0
1.21.9
7
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.23.0
1.21.9
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.23.0
1.21.9
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.23.0
1.21.9
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.21.9
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.23.0
1.21.9
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.21.9
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.23.0
1.21.9
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.23.0
1.21.9
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.23.0
1.21.9
6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.21.9
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.23.0
1.21.9
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.23.0
1.21.9
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.23.0
1.21.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.23.0
1.21.9
5
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.21.9
5
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.21.9
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.21.9
5
library/redis:5:5.0fc5ecd863862
stdlib@go1.16.7
1.21.9
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.23.0
1.21.9
5
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.21.9
5
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.23.0
1.21.9
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.23.0
1.21.9
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.21.9
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.23.0
1.21.9
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.23.0
1.21.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.23.0
1.21.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.23.0
1.21.9
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.23.0
1.21.9
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.23.0
1.21.9
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.23.0
1.21.9
4
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.23.0
1.21.9
4
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.23.0
1.21.9
4
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.23.0
1.21.9
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.23.0
1.21.9
4
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.23.0
1.21.9
4
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.23.0
1.21.9
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.21.9
4
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.23.0
1.21.9
4

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.