StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm3
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.19+esm11
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.19+esm11
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm11
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm11
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/0xemma/reddark:main2a115e991894
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
curl@7.83.1-r4
8.5.0-r0
1
ghcr.io/axoflow/axosyslog:4.5.0aa7831e207cd
curl@8.4.0-r0
8.5.0-r0
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.21
1
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
curl@7.83.1-r2
8.5.0-r0
1
ghcr.io/conductionnl/contactcatalogus-nginx:latest480c84fa9e63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/conductionnl/digispoof-interface-nginx:latest8fa4597217a4
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/eav-component-nginx:latestd785c893096c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/conductionnl/medewerkercatalogus-nginx:latest06c3b27462e6
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/conductionnl/skeleton-pip:devce1ebe9387a2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/user-component-nginx:latestb721579df8c3
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/conductionnl/waardepapieren-nginx:latestaf31cf6cd59f
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
curl@8.3.0-r0
8.5.0-r0
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
curl@7.87.0-r1
8.5.0-r0
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/data-fair/metrics:0a8d40779eeae
curl@8.1.2-r0
8.5.0-r0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
curl@7.83.1-r2
8.5.0-r0
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
curl@7.80.0-r1
8.5.0-r0
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.