StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.21
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.21
1
openverso/ueransim:3.2.6733f1232b7d3
curl@7.83.1-r3
8.5.0-r0
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm3
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
owntracks/recorder:0.9.370105145f719
curl@7.83.1-r4
8.5.0-r0
1
oxfordsemantic/rdfox:5.6db17910eb855
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
1
pecan/web:1.7.2814d678c5550
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
penpotapp/frontend:2.2.18974882a0542
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
curl@7.76.1-26.el9_3.2
0:7.76.1-26.el9_3.3
1
phntom/binaryvision-tlo-static:0.0.4e8b9ac93a3dd
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
phntom/chartmuseum:v0.16.053883b65d9b7
curl@8.2.0-r1
8.5.0-r0
1
phntom/email-manager:0.1.22d8e2a9f2f085
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
1
phntom/external-dns-host-network:0.0.123adadbac8443
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
phntom/mattermost-defaultbackend:6.4.0c318dc90a4bf
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.15
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
curl@7.86.0-r1
8.5.0-r0
1
photoprism/photoprism:220629-jammy2954334adbda
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
phpmyadmin/phpmyadmin:5.138437e021deb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
pihole/pihole:2023.05.0b83258064f54
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
curl@7.47.0-1ubuntu2.15
7.47.0-1ubuntu2.19+esm11
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
curl@7.83.1-r1
8.5.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.23.17-nginx-3479ada675515f
curl@8.2.1-r0
8.5.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.22.17-nginx-34b85e437ae261
curl@8.2.1-r0
8.5.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.21.14-nginx-33fa8f5906d36a
curl@8.2.1-r0
8.5.0-r0
1
postgis/postgis:15-3.3-alpine4738bee21eb6
curl@8.2.1-r0
8.5.0-r0
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
curl@7.83.1-r4
8.5.0-r0
1
pozetroninc/keydb:v6.0.1653ae64f29da8
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.24+esm3
1
prefapp/nginx-proxified:latestf4d026fd9a26
curl@7.83.1-r3
8.5.0-r0
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
curl@7.88.1-r1
8.5.0-r0
1
project2team4/react:latest3ff031a08887
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
psorab/elibrary:latest53b68896c4ce
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.21
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
curl@7.68.0-1ubuntu2.13
7.68.0-1ubuntu2.21
1
qumine/minecraft-server:v0.1.15c0b650d51132
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
rabeh/apibootspring:1.0941007b6946e
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.15
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.19+esm11
1
remche/shinyproxy:2.6.18bcda8a04d3b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
reportportal/migrations:5.7.0da5d8e1395fe
curl@7.80.0-r0
8.5.0-r0
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
reportportal/service-ui:5.7.20a08784eb901
curl@7.83.1-r1
8.5.0-r0
1
rezachalak/bzen-mongo:1.0.034f694325191
curl@7.68.0-1ubuntu2.19
7.68.0-1ubuntu2.21
1
rm3l/dev-feed-api:latest9a7f732245a3
curl@7.76.1-23.el9_2.4
0:7.76.1-23.el9_2.6
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
robmarkcole/deepstack-ui:latest410275726459
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
robotshop/rs-dispatch:latestde81f1d07b02
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
robotshop/rs-mongodb:latest119b545823cd
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.