StackRadar

CVE-2023-45289

Medium

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,112
of 17,821 indexed, latest versions
Container images
2,463
deployed by those charts
Fix available
1 of 2
affected packages

Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http

Carried by container images the latest versions of 2,112 of 17,821 indexed charts deploy, on 2,463 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+122 more1.21.82,463
OSV records
DEBIAN-CVE-2023-45289GO-2024-2600
Also known as
BIT-golang-2023-45289

Charts affected

2,112 by stars
ChartLatestAffected imagesRadar Score
kubedb-provider-gcpappscodeVerified publisher2026.7.101 of 2See more

kubedb-provider-gcp appscode 2026.7.10

1 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
stdlib@go1.19.1
1.21.8

Open the chart page →

3,041
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
stdlib@go1.17.8
1.21.8

Open the chart page →

2,055
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
stdlib@go1.19.1
1.21.8

Open the chart page →

2,804
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
stdlib@go1.20.5
1.21.8

Open the chart page →

2,724
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
stdlib@go1.19.9
1.21.8

Open the chart page →

2,751
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.01 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.8

Open the chart page →

1,298
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
stdlib@go1.22.0
1.21.8

Open the chart page →

2,405
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
stdlib@go1.19.4
1.21.8

Open the chart page →

4,192
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.21.8

Open the chart page →

2,203
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.21.8

Open the chart page →

824
stash-communityappscodeVerified publisher0.42.01 of 4See more

stash-community appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.21.8

Open the chart page →

3,679
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.21.8
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.21.8

Open the chart page →

2,740
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
stdlib@go1.21.1
1.21.8

Open the chart page →

5,720
appwriteappwrite-helmVerified publisher1.3.22 of 8See more

appwrite appwrite-helm 1.3.2

2 of the 8 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.21.8
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.21.8

Open the chart page →

9,859
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
stdlib@go1.16.4
1.21.8

Open the chart page →

5,213
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.21.8

Open the chart page →

7,710
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
stdlib@go1.19.3
1.21.8
stakater/reloader:v1.0.15f4b87a8e56d4
stdlib@go1.20.1
1.21.8
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
stdlib@go1.18.10
1.21.8
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.21.8
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.21.8
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.21.8
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.21.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
stdlib@go1.19.4
1.21.8

Open the chart page →

23,478
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
stdlib@go1.19.2
1.21.8

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
stdlib@go1.17.11
1.21.8
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
stdlib@go1.17.10
1.21.8
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
stdlib@go1.17.3
1.21.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
stdlib@go1.18.3
1.21.8

Open the chart page →

8,634
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
stdlib@go1.21.5
1.21.8
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
stdlib@go1.21.5
1.21.8

Open the chart page →

12,896
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.21.8

Open the chart page →

5,538
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
stdlib@go1.17.13
1.21.8
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.21.8
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.21.8
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.21.8

Open the chart page →

194,560
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
stdlib@go1.17.13
1.21.8
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.21.8
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.21.8
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.21.8

Open the chart page →

194,560
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.21.8

Open the chart page →

3,806
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.21.8

Open the chart page →

9,452
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.21.8

Open the chart page →

4,388
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.21.8

Open the chart page →

13,434
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.21.8

Open the chart page →

10,190
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
stdlib@go1.18.6
1.21.8
kong/kubernetes-ingress-controller:2.35e66021b64a8
stdlib@go1.18
1.21.8

Open the chart page →

88,283
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
stdlib@go1.17.12
1.21.8
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.21.8
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.21.8
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
stdlib@go1.18.3
1.21.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.21.8

Open the chart page →

8,594
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.21.8

Open the chart page →

8,079
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.21.8
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.21.8
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.21.8

Open the chart page →

46,145
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.21.8
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.21.8

Open the chart page →

32,866
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.21.8

Open the chart page →

1,765
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
stdlib@go1.19.1
1.21.8

Open the chart page →

5,644
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
rclone/rclone:1.56.0f2fc45c8bc57
stdlib@go1.16.6
1.21.8

Open the chart page →

6,516
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.21.8

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
stdlib@go1.18.10
1.21.8

Open the chart page →

9,487
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
stdlib@go1.15.3
1.21.8
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.21.8

Open the chart page →

6,511
alertmanager-discordatrox3.1.01 of 1See more

alertmanager-discord atrox 3.1.0

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.21.8

Open the chart page →

587
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
stdlib@go1.13.10
1.21.8

Open the chart page →

7,574
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.21.8

Open the chart page →

1,728
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
stdlib@go1.19.7
1.21.8

Open the chart page →

5,084
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
stdlib@go1.19.3
1.21.8

Open the chart page →

6,980
kubeslice-workeraveshaVerified publisher1.5.01 of 14See more

kubeslice-worker avesha 1.5.0

1 of the 14 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
stdlib@go1.20.3
1.21.8

Open the chart page →

1,645
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.21.8

Open the chart page →

861
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
stdlib@go1.17.3
1.21.8

Open the chart page →

2,488
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.21.8

Open the chart page →

2,947
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
stdlib@go1.19.3
1.21.8
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
stdlib@go1.19.3
1.21.8

Open the chart page →

2,967
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-45289.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
stdlib@go1.15.3
1.21.8

Open the chart page →

2,141

Container images carrying it

2,463 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.21.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.21.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.21.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.21.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.21.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.21.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.21.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.21.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.21.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.21.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.21.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.21.8
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.