StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
istio/proxyv2:1.9.687a9db561d2e
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
istio/proxyv2:1.10.088c6c693e67a
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
istio/proxyv2:1.14.1df69c1a7af7c
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
jacobalberty/unifi:v7.1.664a3616625dda
curl@7.58.0-2ubuntu3.18
7.58.0-2ubuntu3.24+esm3
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
curl@7.58.0-2ubuntu3.24
7.58.0-2ubuntu3.24+esm3
1
jacobalberty/unifi:5.10.19c409924e2463
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm11
1
jakowenko/double-take:1.6.0b858bac9e32a
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
jedi132000/nextapp:latestdc2a81e92f23
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
jellyfin/jellyfin:10.8.1305a9734d7e83
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u11
1
jellyfin/jellyfin:10.8.1ee24f4459a40
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
jmferrer/azure-devops-agent:latest030f68ec6998
curl@7.47.0-1ubuntu2.14
7.47.0-1ubuntu2.19+esm11
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u11
1
jupyterhub/configurable-http-proxy:4.5.1723028bf9b3c
curl@7.80.0-r0
8.5.0-r0
1
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
curl@8.2.1-r0
8.5.0-r0
1
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
curl@7.83.1-r3
8.5.0-r0
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
1
kfirfer/king:latestc05d9fc7ae77
curl@8.2.1-r0
8.5.0-r0
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
kfirfer/scripts:0.0.2481e5c4e5d70e
curl@7.80.0-r5
8.5.0-r0
1
kobotoolbox/kobocat:2.022.24ab15679454415
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
curl@7.68.0-1ubuntu2.16
7.68.0-1ubuntu2.21
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
curl@7.80.0-r6
8.5.0-r0
1
kubebb/hello-world:0.1.0b746824819f3
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
curl@7.83.1-r2
8.5.0-r0
1
kubegems/bitnami-shell:12-debian-12-r24e42e3aaacdd3
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
kubegems/chatgpt-api:latestf3c492a938ad
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
kubegems/kubectl:latestc3b4be9a54f5
curl@7.87.0-r1
8.5.0-r0
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm3
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
curl@7.83.1-r3
8.5.0-r0
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
curl@8.2.1-r0
8.5.0-r0
1
kyso/jupyter-diff:latest82299a9e5a86
curl@8.2.1-r0
8.5.0-r0
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
curl@7.86.0-r1
8.5.0-r0
1
library/cassandra:3.11.10b095ff3248c6
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
library/elasticsearch:7.17.0332c6d416808
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
library/elasticsearch:7.17.8fdc73b3249c1
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
library/flink:1.14.6-scala_2.122461f02672b3
curl@7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.15
1
library/httpd:2.4.54ee2117e77c35
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
library/influxdb:2.7.4-alpinea10d46445d68
curl@8.4.0-r0
8.5.0-r0
1
library/kibana:7.17.8c5781ba340ef
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
library/kibana:7.17.3e2e2031c15be
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
library/logstash:7.17.817a4f64e9cf5
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
library/mongo:4.4.1305678ae4e5e1
curl@7.68.0-1ubuntu2.10
7.68.0-1ubuntu2.21
1
library/mongo:4.4-bionic3d0e6df9fd5b
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.