StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
79
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm3
79
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm11
11
library/mongo:5.0.6-focal8e70544b6c76
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
10
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
curl@7.83.1-r5
8.5.0-r0
10
wurstmeister/kafka:latest2d4bbf9cc83d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
6
library/nginx:1.21:1.21.62bcabc23b454
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
6
oomk8s/readiness-check:2.0.07daa08b81954
curl@7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.19+esm11
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
curl@7.80.0-r6
8.5.0-r0
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
6
quay.io/devtron/kubectl:latest2ad610626658
curl@7.83.1-r3
8.5.0-r0
6
natsio/nats-box:0.14.1a67913df95f1
curl@8.4.0-r0
8.5.0-r0
5
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
curl@7.83.1-r4
8.5.0-r0
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
curl@7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.19+esm11
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm11
4
hyperledger/fabric-tools:2.4b1194f509085
curl@7.83.1-r6
8.5.0-r0
4
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
4
library/mongo:4.2.12-bionic628741415fc9
curl@7.58.0-2ubuntu3.12
7.58.0-2ubuntu3.24+esm3
4
library/mongo:4.4.66efa05203990
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
4
mastercloudapps/planner:v1.2340a950b311b2
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.15
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
curl@7.58.0-2ubuntu3.12
7.58.0-2ubuntu3.24+esm3
4
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
3
codeurjc/planner:v1.0800cf520c245
curl@7.81.0-1ubuntu1.8
7.81.0-1ubuntu1.15
3
dgraph/dgraph:v21.12.03b55ea83fffe
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
curl@7.83.1-r4
8.5.0-r0
3
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
curl@7.80.0-r0
8.5.0-r0
3
library/nginx:1.22.0f0d28f204785
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
3
library/solr:8.11.18c5f7881cebb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.5.0-r0
3
selenium/hub:3.141.5902f251d48d5f
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
3
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
3
signoz/zookeeper:3.7.1fcc4a3288154
curl@7.74.0-1.3+deb11u9
7.74.0-1.3+deb11u11
3
xenondb/percona:5.7.330e26872a2b67
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u11
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
curl@7.88.1-10
7.88.1-10+deb12u5
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
curl@7.81.0-1ubuntu1.7
7.81.0-1ubuntu1.15
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
curl@7.47.0-1ubuntu2.19
7.47.0-1ubuntu2.19+esm11
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.15
3
quay.io/devtron/svn-git-sync:v78e54bc2d261f
curl@7.83.1-r1
8.5.0-r0
3
quay.io/jupyterhub/configurable-http-proxy:4.6.1fd916f75415f
curl@8.4.0-r0
8.5.0-r0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
curl@7.83.1-r4
8.5.0-r0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
curl@8.1.2-r0
8.5.0-r0
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.5.0-r0
2
assistiot/fl_repository_db:latestad8f72108636
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
2
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.