StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,790 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,790 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
tautulli/tautulli:v2.7.7c4da15f058ea
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
temporalio/admin-tools:1.22.4258958fe2ff2
curl@8.4.0-r0
8.5.0-r0
1
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.5.0-r0
1
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.5.0-r0
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.19+esm11
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
curl@8.3.0-r0
8.5.0-r0
1
thirtythreeforty/neolink:latestf564c4f538de
curl@8.0.1-r2
8.5.0-r0
1
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.15
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.15
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
curl@7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.15
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.19+esm11
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
torrespro/mca-worker:2.0.06d3bd305a1ba
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
tpdock/freeradius:2.2.93da600c95a49
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.19+esm11
1
trinodb/trino:405ee80ab5eeab2
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
udhos/forward:1.1.312e120d39fdb
curl@8.1.2-r0
8.5.0-r0
1
udhos/prime:1.0.0e432012dd34a
curl@8.1.2-r0
8.5.0-r0
1
vaultwarden/server:1.27.0-alpine7cd450642c54
curl@7.87.0-r0
8.5.0-r0
1
vaultwarden/server:1.29.1c2849f8189e4
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
curl@7.58.0-2ubuntu3.22
7.58.0-2ubuntu3.24+esm3
1
vlebediantsev/config-server-another:lateste7f20450d2ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
vlebediantsev/logic-ms:latestdf8bf38c535b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
vlebediantsev/notes-admin-front:latest007c6670ff48
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
vlebediantsev/notes-project-front:latest945675fd2636
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
vlebediantsev/registration-ms-final:latest427af418b75e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
volkerraschek/postfixadmin:3.3.13c4f10aebf87b
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
voltha/voltha-onos:5.1.8e038acb950d3
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm3
1
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.5.0-r0
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.21
1
wavefronthq/proxy:9.2d1064d28f6eb
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm3
1
wazuh/wazuh-manager:4.4.121994f40e0da
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.21
1
wistefan/mvf:lateste0887302b2d8
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
xeotek/kadeck:4.2.94c6b04d9ce55
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.21
1
xtrendence/cryptofolio:V.2.2.0e6e6612bb94c
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
xvilo/php:8.2-composera138e57d3204
curl@7.87.0-r1
8.5.0-r0
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.