StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.5.0-r0
1
aquasec/trivy:0.43.1944a04445179
curl@8.1.2-r0
8.5.0-r0
1
aquasec/trivy:0.32.0973d0df16189
curl@7.83.1-r3
8.5.0-r0
1
archish27/python-fastapi-postgres:latest6610071a2101
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
aroralalit/student-producer:1.0.02a094f597b36
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.21
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
curl@7.83.1-r3
8.5.0-r0
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
assistiot/location_processing:lateste9bae124095f
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
assistiot/open_api_kong:1.0.03fe850384689
curl@7.83.1-r4
8.5.0-r0
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
curl@7.68.0-1ubuntu2.19
7.68.0-1ubuntu2.21
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
curl@7.83.1-r3
8.5.0-r0
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.21
1
atlassian/confluence-server:7.10.03b9222ab32ef
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
atomix/atomix:3.1.127738ff4f5c63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
avinash263/pyredis263:latestaa2b8727f1a6
curl@7.88.1-10
7.88.1-10+deb12u5
1
avzini/web-app:latestf40b30210ed0
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
azhar008/flaskapplication:latesta1e827b0adea
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
bicarus/wg-access-server:v0.8.206cab48e9334
curl@7.83.1-r3
8.5.0-r0
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
bitnamilegacy/kubectl:1.22.13d0e426ccff33
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
blockscout/blockscout:5.1.5c365a8f2dc12
curl@7.83.1-r5
8.5.0-r0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
buntha/mlflow:2.1.1154542cc3083
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
casbin/casdoor:v1.224.066f836ef778b
curl@7.87.0-r1
8.5.0-r0
1
chaosnative/cle-frontend:2.7.007b82a82a702
curl@7.80.0-r0
8.5.0-r0
1
charmcli/soft-serve:v0.4.039523c1a6ba8
curl@7.83.1-r2
8.5.0-r0
1
chetangautamm/repo:sipp.v3e7f7049e1544
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
1
cheyang/distributed-tf:1.6.046cc34755493
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.19+esm11
1
chubaofs/cfs-client:3.2.015ff74209ce7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
chubaofs/cfs-server:3.2.0205030e045f2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
clastix/kubectl:v1.2187fabaccb3a6
curl@7.80.0-r0
8.5.0-r0
1
clastix/kubectl:v1.22d0376d87ac6b
curl@7.80.0-r0
8.5.0-r0
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
curl@8.1.2-r0
8.5.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.