StackRadar

CVE-2023-45311

Critical

Advisory

Published 6 Oct 2023In the index since 8 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 2
affected packages

Code injection in fsevents

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2no fix listed6
fseventsnpm1.1.2, 1.2.71.2.113
OSV records
GHSA-8r6j-v8pm-fqw3UBUNTU-CVE-2023-45311

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
fsevents@1.1.2
1.2.11

Open the chart page →

4,069
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

12,779
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
fsevents@1.2.7
1.2.11

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

27,417
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
npm@9.2.0~ds1-2
no fix listed

Open the chart page →

13,220
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
fsevents@1.2.7
1.2.11

Open the chart page →

12,907
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

17,779
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

36,215
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-45311.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

10,902

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
conduction/conduction-ui-app:devd591f5e6f2a9
fsevents@1.2.7
1.2.11
1
daskdev/dask-notebook:1.1.0052630f5ca04
fsevents@1.2.7
1.2.11
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
npm@9.2.0~ds1-2
no fix listed
1
konradkleine/docker-registry-frontend:v2181aad54ee64
fsevents@1.1.2
1.2.11
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed
1
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.