StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
haveagitgat/tdarr:2.00.181256348872ce
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
curl@7.68.0-1ubuntu2.19
7.68.0-1ubuntu2.21
1
hazelcast/hazelcast:5.3.18fe26efde8e1
curl@8.2.1-r0
8.5.0-r0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
helga09/php_shoes_ukr:v1.1.1e283539bcb8c
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
hiboxsystems/marge-bot:0.11.07235809b43b3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
hiboxsystems/marge-bot:0.12.1a96c10b61a59
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
hivemq/hivemq4:dns-4.5.144d194450d48e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.15
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
curl@8.3.0-r0
8.5.0-r0
1
homeassistant/home-assistant:2023.12.48d000332b09b
curl@8.4.0-r0
8.5.0-r0
1
housewrecker/gaps:latestf417dd0a7547
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
curl@8.1.2-r0
8.5.0-r0
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
curl@7.58.0-2ubuntu3.12
7.58.0-2ubuntu3.24+esm3
1
hugohg34/server:0.0.2503e5d8960ff
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
hugohg34/toposervice:0.0.2812a03b3f274
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
curl@7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.19+esm11
1
i4trust/activation-service:2.2.09f3719176893
curl@8.1.2-r0
8.5.0-r0
1
ianw/quickchart:v1.7.1dc49dd460c37
curl@7.80.0-r3
8.5.0-r0
1
ibarreche/cloud-back-ci:lateste16a469c5791
curl@7.80.0-r0
8.5.0-r0
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
curl@7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.19+esm11
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
curl@7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.19+esm11
1
ibmcom/microclimate-theia:lateste17bdccc5030
curl@7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.19+esm11
1
ibmcom/skydive:0.22.0395e60cc6e3d
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.24+esm3
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.21
1
invoiceninja/invoiceninja:5.6.241437916dee01
curl@8.1.2-r0
8.5.0-r0
1
iomesh/prepare-csi:v1.0.3-rc0063b18afb6a1
curl@8.1.2-r0
8.5.0-r0
1
iomesh/prepare-csi:v1.0.24206d42b92f1
curl@8.1.2-r0
8.5.0-r0
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
curl@7.68.0-1ubuntu2.13
7.68.0-1ubuntu2.21
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
istio/install-cni:1.10.32232f365aed6
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
istio/node-agent-k8s:1.2.9268ab879ea51
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm11
1
istio/operator:1.10.3655eefa11c84
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
istio/operator:1.12.06cfce8a071b9
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
istio/operator:1.18.270f9d1fe5fff
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.15
1
istio/pilot:1.10.0294ca55bd1cc
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
istio/pilot:1.16.0ac0284d75ec9
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
istio/pilot:1.2.9c09319753454
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm11
1
istio/pilot:1.17.1ce9d87606701
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.15
1
istio/pilot:1.15.2db08d6963975
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.15
1
istio/pilot:1.10.3e7e110a421c2
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
istio/proxyv2:1.2.90c78be035e98
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.19+esm11
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.