StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
curl@8.2.1-r0
8.5.0-r0
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
curl@7.58.0-2ubuntu3.16
7.58.0-2ubuntu3.24+esm3
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
curl@7.58.0-2ubuntu3.14
7.58.0-2ubuntu3.24+esm3
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
curl@8.2.1-r0
8.5.0-r0
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
curl@7.87.0-r2
8.5.0-r0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
curl@7.83.1-r4
8.5.0-r0
1
ghcr.io/mroxso/pollstr:latest0b4f97faa3d0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
curl@8.0.1-r2
8.5.0-r0
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
ghcr.io/pascaliske/traefik-errors:1.1.00cf31753ce57
curl@8.1.2-r0
8.5.0-r0
1
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
curl@8.3.0-r0
8.5.0-r0
1
ghcr.io/reitermarkus/strongswan:v1.0.0e7a8afe6e6eb
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
curl@8.0.1-r0
8.5.0-r0
1
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
curl@7.83.1-r2
8.5.0-r0
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
curl@7.80.0-r0
8.5.0-r0
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
curl@7.80.0-r1
8.5.0-r0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
curl@7.58.0-2ubuntu3.18
7.58.0-2ubuntu3.24+esm3
1
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.15
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.