StackRadar

CVE-2023-45803

Medium

Advisory

Published 17 Oct 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
512
of 17,781 indexed, latest versions
Container images
539
deployed by those charts
Fix available
4 of 4
affected packages

urllib3's request body not stripped after redirect from 303 status changes request method to GET

Carried by container images the latest versions of 512 of 17,781 indexed charts deploy, on 539 images.

Affected packageAffected versionsFixed inImages
urllib3pypi1.7.1, 1.10.2, 1.13.1, 1.19.1+37 more1.26.18, 2.0.7518
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+15 more8.1.1-2ubuntu0.6+esm6, 9.0.1-2.3~ubuntu1.18.04.8+esm2, 20.0.2-5ubuntu1.10, 22.0.2+dfsg-1ubuntu0.4+1 more67
python-urllib3deb1.7.1-1build1, 1.7.1-1ubuntu4, 1.13.1-2ubuntu0.16.04.1, 1.13.1-2ubuntu0.16.04.2+7 more1.13.1-2ubuntu0.16.04.4+esm1, 1.22-1ubuntu0.18.04.2+esm1, 1.24.1-1+deb10u2, 1.25.8-2ubuntu0.3+2 more39
py3-urllib3apk1.26.7-r0, 1.26.9-r0, 1.26.12-r0, 1.26.15-r11.26.18-r012
OSV records
ALPINE-CVE-2023-45803DEBIAN-CVE-2023-45803GHSA-g4mx-q9vg-27p4UBUNTU-CVE-2023-45803DLA-3649-1
Also known as
PYSEC-2023-212, USN-6473-1, USN-6473-2, USN-7762-1

Charts affected

512 by stars
ChartLatestAffected imagesRadar Score
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
24.0+dfsg-1ubuntu1.3

Open the chart page →

7,628
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
urllib3@1.24.1
1.26.18

Open the chart page →

11,405
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
urllib3@1.26.5
1.26.18

Open the chart page →

11,119
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
urllib3@1.26.8
1.26.18

Open the chart page →

2,670
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
urllib3@1.26.3
1.26.18

Open the chart page →

4,086
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
urllib3@1.26.12
1.26.18

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
urllib3@1.24.2
1.26.18

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
urllib3@1.24.2
1.26.18

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
urllib3@1.26.3
1.26.18

Open the chart page →

1,843
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
urllib3@2.0.4
2.0.7

Open the chart page →

5,542
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
urllib3@1.25.11
1.26.18

Open the chart page →

2,643
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-45803.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
urllib3@1.26.15
1.26.18

Open the chart page →

1,838

Container images carrying it

539 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
alexvm6/generator:latestfb99ee4f760a
urllib3@2.0.2
2.0.7
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python-pip@9.0.1-2.3~ubuntu1.18.04.5
urllib3@1.26.9
9.0.1-2.3~ubuntu1.18.04.8+esm2
1.26.18
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
urllib3@1.26.15
1.26.18
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
urllib3@1.26.15
1.26.18
1
alpine/k8s:1.22.600ac10bcb759
urllib3@1.26.9
1.26.18
1
alpine/k8s:1.27.321b24e6bf801
urllib3@1.26.16
1.26.18
1
alpine/k8s:1.18.16a41efe02a041
urllib3@1.26.6
1.26.18
1
alpine/k8s:1.28.2fc059f056ad0
urllib3@2.0.6
2.0.7
1
amancevice/superset:0.28.1c8c04bfe3d66
urllib3@1.22
1.26.18
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
urllib3@1.24.3
1.26.18
1
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
urllib3@1.25.10
1.26.18
1
amundsendev/amundsen-search:2.4.099dda9502c3e
urllib3@1.22
1.26.18
1
anchore/anchore-engine:v0.10.0bde9eedf639d
urllib3@1.25.9
1.26.18
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
urllib3@1.25.8
1.26.18
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
python-pip@22.0.2+dfsg-1ubuntu0.3
22.0.2+dfsg-1ubuntu0.4
1
andrianrf/backoffice:latest047a7837651e
urllib3@1.24.2
1.26.18
1
apache/couchdb:2.39f895c8ae371
urllib3@1.19.1
1.26.18
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
python-pip@22.0.2+dfsg-1ubuntu0.3
22.0.2+dfsg-1ubuntu0.4
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
python-pip@20.0.2-5ubuntu1.6
urllib3@1.26.9
20.0.2-5ubuntu1.10
1.26.18
1
apachepulsar/pulsar:2.6.14db6ff0b4045
urllib3@1.25.10
1.26.18
1
apachepulsar/pulsar:2.9.0d056c89b7131
urllib3@1.26.7
1.26.18
1
apachepulsar/pulsar:2.8.2d538416d5afe
urllib3@1.26.7
1.26.18
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
urllib3@1.26.6
1.26.18
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
urllib3@1.26.5
1.26.18
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
urllib3@1.24.2
1.26.18
1
apsl/thumbor:6.7.051e2de5c2c70
urllib3@1.25.7
1.26.18
1
aquasec/kube-hunter:1950bf607ce9308
urllib3@1.24.1
1.26.18
1
arunvelsriram/utils:latest655ad18fd8d6
python-pip@24.0+dfsg-1ubuntu1.2
24.0+dfsg-1ubuntu1.3
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
urllib3@1.26.5
1.26.18
1
assistiot/fl_local_operations_inference:latest0518b63a2e69
urllib3@1.26.16
1.26.18
1
assistiot/fl_repository:latest0fce3ea719a5
urllib3@1.26.12
1.26.18
1
assistiot/fl_training_collector:latest792715dd3084
urllib3@1.26.7
1.26.18
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
urllib3@1.26.16
1.26.18
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
python-pip@20.0.2-5ubuntu1.8
python-urllib3@1.25.8-2ubuntu0.2
urllib3@1.25.8
20.0.2-5ubuntu1.10
1.25.8-2ubuntu0.3
1.26.18
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
urllib3@1.26.8
1.26.18
1
bbvalabs/sensitive-data:1.0.13ea299ae63c0
urllib3@1.26.4
1.26.18
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
urllib3@1.26.5
1.26.18
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.10
1
billimek/comcastusage-for-influxdb:latest801bba1228ac
urllib3@1.24
1.26.18
1
billimek/prometheus-uptimerobot-exporter:0.0.1f14ccd7aad0e
urllib3@1.25.9
1.26.18
1
billimek/sb6183-for-influxdb:latestbf8158556035
urllib3@1.22
1.26.18
1
blacktop/httpie:latestfc5e68e2f5ab
urllib3@1.22
1.26.18
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.10
1
bootc/puppetboard:1.1.0f1383295e7be
urllib3@1.25.8
1.26.18
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python-urllib3@1.25.8-2ubuntu0.1
urllib3@1.25.8
1.25.8-2ubuntu0.3
1.26.18
1
buildkite/agent:3.25.0aec38cfaae0e
urllib3@1.24.3
1.26.18
1
buntha/mlflow:2.1.1154542cc3083
urllib3@1.26.13
1.26.18
1
camerahub/camerahub:0.36.23a5af37dd6e1b
urllib3@1.26.15
1.26.18
1
camptocamp/bucket-cloner:latestacfafc308d88
urllib3@1.26.6
1.26.18
1
camptocamp/ekorre:0.1.035c91d5fda04
urllib3@1.25.8
1.26.18
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.