StackRadar

CVE-2023-4806

Medium

Advisory

Published 18 Sept 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.016
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
604
of 17,787 indexed, latest versions
Container images
556
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 604 of 17,787 indexed charts deploy, on 556 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+20 more2.23-0ubuntu11.3+esm5, 2.27-3ubuntu1.6+esm1, 2.31-0ubuntu9.14, 2.35-0ubuntu3.5+1 more549
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
OSV records
DEBIAN-CVE-2023-4806UBUNTU-CVE-2023-4806
Also known as
USN-6541-1, USN-6541-2

Charts affected

604 by stars
ChartLatestAffected imagesRadar Score
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2023-4806.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14

Open the chart page →

15,230
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2023-4806.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
openebs/node-disk-operator:2.1.06afe2123c457
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5

Open the chart page →

10,489
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-4806.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm1

Open the chart page →

2,458
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2023-4806.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
glibc@2.27-3ubuntu1.4
2.27-3ubuntu1.6+esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14

Open the chart page →

9,207

Container images carrying it

556 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/proxyv2:1.10.3a78b7a165744
glibc@2.27-3ubuntu1.4
2.27-3ubuntu1.6+esm1
2
library/cassandra:3.11.65aa8400b4b3b
glibc@2.27-3ubuntu1.2
2.27-3ubuntu1.6+esm1
2
library/elasticsearch:7.17.35e6ac15bf6a5
glibc@2.31-0ubuntu9.7
2.31-0ubuntu9.14
2
library/mariadb:10.8.30abf60f81588
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
library/mongo:4.2.358b25d51baa1
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm1
2
library/python:3.7eedf63967cdb
glibc@2.36-9+deb12u1
2.36-9+deb12u3
2
library/rabbitmq:3.12.1-managementf020c06da226
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
library/ubuntu:16.04:xenial1f1a2d56de1d
glibc@2.23-0ubuntu11.3
2.23-0ubuntu11.3+esm5
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
glibc@2.23-0ubuntu11
2.23-0ubuntu11.3+esm5
2
mbentley/omada-controller:4.3f4e682274bed
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm1
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
glibc@2.31-0ubuntu9.1
2.31-0ubuntu9.14
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm1
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
glibc@2.31-0ubuntu9.7
2.31-0ubuntu9.14
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
glibc@2.23-0ubuntu10
2.23-0ubuntu11.3+esm5
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
openebs/node-disk-operator:2.1.06afe2123c457
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.14
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
glibc@2.35-0ubuntu3
2.35-0ubuntu3.5
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
wurstmeister/zookeeper:latest7a7fd44a7210
eglibc@2.19-0ubuntu6.3
no fix listed
2
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
glibc@2.23-0ubuntu9
2.23-0ubuntu11.3+esm5
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
glibc@2.27-3ubuntu1.2
2.27-3ubuntu1.6+esm1
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm1
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm1
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
glibc@2.35-0ubuntu3
2.35-0ubuntu3.5
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.14
2
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
glibc@2.36-9+deb12u1
2.36-9+deb12u3
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm1
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
glibc@2.31-0ubuntu9.1
2.31-0ubuntu9.14
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
1
akaunting/akaunting:3.0.1552811b36ec3a
glibc@2.36-9
2.36-9+deb12u3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm1
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
glibc@2.35-0ubuntu3.4
2.35-0ubuntu3.5
1
anguda/ant-media:2.5c435285fc241
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.14
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
glibc@2.36-9+deb12u1
2.36-9+deb12u3
1
apache/iotdb:0.13.3-nodeafa47bf1692a
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.14
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
1
apachepulsar/pulsar:2.9.0d056c89b7131
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
1
apachepulsar/pulsar:2.8.2d538416d5afe
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
1
apache/skywalking-oap-server:9.2.0133d35d2c263
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
1
apache/skywalking-ui:9.2.0295f1dc87d98
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.5
1
apache/skywalking-ui:8.9.180530f0308a5
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.