StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:5.0.14-focal50cae5081ab4
curl@7.68.0-1ubuntu2.15
7.68.0-1ubuntu2.21
1
library/mongo:4.2699d652ed674
curl@7.58.0-2ubuntu3.24
7.58.0-2ubuntu3.24+esm3
1
library/mongo:4.2.16ca49afbcb2b
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm3
1
library/mongo:6.0.271a63fc2438e
curl@7.68.0-1ubuntu2.13
7.68.0-1ubuntu2.21
1
library/mongo:5.0.217c81758cb295
curl@7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.21
1
library/mongo:4.2.21-bionic9cb28f7291d9
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm3
1
library/mongo:4.4.18d23ec07162ca
curl@7.68.0-1ubuntu2.15
7.68.0-1ubuntu2.21
1
library/monica:3.7.0-apacheceb1ba4196ab
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
library/nginx:1.23.03536d368b898
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
library/nginx:1.23.2-alpine455c39afebd4
curl@7.83.1-r4
8.5.0-r0
1
library/nginx:1.25.167f9a4f10d14
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
library/nginx:1.23.2ab589a3c466e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
library/nginx:1.23.3f4e3b6489888
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
library/nginx:1.23f5747a42e3ad
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
library/php:7-fpm-alpine0aeb129a60da
curl@7.83.1-r4
8.5.0-r0
1
library/php:7.3-apacheb9872cd287ef
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
library/solr:8.7.0d124efd81fbb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
library/sonarqube:10.0.0-communityef9723cf4fe4
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.15
1
library/telegraf:1.20.428e98eece020
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
library/zookeeper:3.8-temurin55d1e5b2e601
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.15
1
librenms/librenms:22.4.14f1f3d667cc7
curl@7.80.0-r0
8.5.0-r0
1
lightbend/curl:7.47.0b0c9894ac8dd
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.19+esm11
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
linuxserver/cloud9:latest45c5fe102ff3
curl@7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.24+esm3
1
linuxserver/code-server:4.10.1a5e43a05ae79
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.15
1
linuxserver/codimd:latestb801bbcf6386
curl@7.58.0-2ubuntu3.12
7.58.0-2ubuntu3.24+esm3
1
linuxserver/deluge:18.04.10ac871624394
curl@7.58.0-2ubuntu3.16
7.58.0-2ubuntu3.24+esm3
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
curl@7.58.0-2ubuntu3.16
7.58.0-2ubuntu3.24+esm3
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.5.0-r0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
curl@7.88.1-r1
8.5.0-r0
1
linuxserver/jellyfin:10.7.72427dde159a2
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.24+esm3
1
linuxserver/plex:1.25.24a13ced2326c
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
linuxserver/unifi-controller:7.3.83ab105cc50322
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.21
1
linuxserver/yq:3.2.26f5b9586a93e
curl@8.2.1-r0
8.5.0-r0
1
litmuschaos/mongo:4.2.899961210d467
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.24+esm3
1
liukunup/jmeter:5.59c079617a81b
curl@7.83.1-r3
8.5.0-r0
1
livekit/ingress:v1.2.21ab01641b366
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.15
1
lnbitsdocker/lnbits-legend:latest26fae6327477
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u11
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
longhornio/longhorn-manager:v1.2.3dca34321452c
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
lsstsqre/exposurelog:0.8.079b00fb67a65
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
lsstsqre/narrativelog:0.1.0ce01de04ce21
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.