StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,787 indexed, latest versions
Container images
1,762
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,787 indexed charts deploy, on 1,762 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,386
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
devtron-enterprisedevtron48.0.011 of 28See more

devtron-enterprise devtron 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackdevtron19.3.02 of 6See more

kube-prometheus-stack devtron 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,507
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.011 of 28See more

devtron-enterprise devtron-labs 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.36 of 11See more

devtron-operator devtron-labs 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackdevtron-labs19.3.02 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,507
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,233
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,806
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2

Open the chart page →

13,031
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/crypto@v0.1.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9

Open the chart page →

21,455
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,632
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,126
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,408
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,046
channelsdoubanVerified publisher1.1.21 of 1See more

channels douban 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
everpcpc/channels:latestb378d137ae8b
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,539
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
curlimages/curl:7.87.0f7f265d5c64e
libssh2@1.10.0-r2
1.11.0-r0
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2

Open the chart page →

24,975
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

3,660
prometheus-memcached-exporterdoubanVerified publisher0.1.31 of 1See more

prometheus-memcached-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,114
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

11,831
tencentcloud-info-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-info-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,325
drogue-cloud-coredrogue-iotVerified publisher0.7.112 of 22See more

drogue-cloud-core drogue-iot 0.7.11

2 of the 22 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
quay.io/keycloak/keycloak:20.0054ef67eb7da
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

55,988
drogue-cloud-examplesdrogue-iotVerified publisher0.7.115 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

5 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
golang.org/x/crypto@v0.0.0-20190911031432-227b76d455e7
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/crypto@v0.14.0
0.17.0
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9

Open the chart page →

30,759
drogue-cloud-metricsdrogue-iotVerified publisher0.7.114 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

4 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

13,558
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

6,914
drone-kubernetes-secretsdroneVerified publisher0.1.41 of 1See more

drone-kubernetes-secrets drone 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,760
temporaldtrdnk-helm-chartsVerified publisher0.35.07 of 13See more

temporal dtrdnk-helm-charts 0.35.0

7 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/crypto@v0.14.0
0.17.0
temporalio/server:1.22.4c0a44c26397b
golang.org/x/crypto@v0.14.0
0.17.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

20,204
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
paramiko@2.11.0
3.4.0

Open the chart page →

1,362
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

2,413
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,679
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

19,820
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,141
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,801
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,179

Container images carrying it

1,762 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
libssh@0.9.6-10.el8_8
paramiko@2.12.0
0:0.9.6-13.el8_8
3.4.0
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
containous/maesh:v1.3.2587162516502
golang.org/x/crypto@v0.0.0-20200317142112-1b76d66859c6
0.0.0-20231218163308-9d2ee975ef9f
1
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/crypto@v0.0.0-20200323165209-0ec3e9974c59
0.0.0-20231218163308-9d2ee975ef9f
1
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.0.0-20231218163308-9d2ee975ef9f
1
countly/countly-server:25.05.4e3c238248f99
libssh@0.9.3-2ubuntu2.2
openssh@1:8.2p1-4ubuntu0.4
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
1
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/crypto@v0.0.0-20210506145944-38f3c27a63bf
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
cribl/cribl:3.0.2762747cb6796
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm3
1
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/crypto@v0.0.0-20190605123033-f99c8df09eb5
0.0.0-20231218163308-9d2ee975ef9f
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
1
ctron/hawkbit-operator:0.1.48fdea8f76499
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
1
curlimages/curl:8.1.15af13420d29b
libssh2@1.10.0-r3
1.11.0-r0
1
curlimages/curl:8.00.19e886c104cae
libssh2@1.10.0-r2
1.11.0-r0
1
curlimages/curl:8.00.0d1658d9c8ef9
libssh2@1.10.0-r2
1.11.0-r0
1
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
1
darkobas/ethexporter:latest62e6464491ba
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
darkobas/tokenexporter:latesta0349a0eedf0
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/crypto@v0.6.0
0.17.0
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/crypto@v0.0.0-20200128174031-69ecbb4d6d5d
paramiko@2.6.0
0.0.0-20231218163308-9d2ee975ef9f
3.4.0
1
datadog/agent:6aad9994de6a7
paramiko@2.12.0
3.4.0
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
datadog/operator:0.3.117f08a860090
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/crypto@v0.0.0-20200709230013-948cd5f35899
0.0.0-20231218163308-9d2ee975ef9f
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
datasaker/dsk-container-agent:latest08b52999f67b
golang.org/x/crypto@v0.14.0
0.17.0
1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
golang.org/x/crypto@v0.14.0
0.17.0
1
datasaker/dsk-node-agent:latest1b95913b6729
golang.org/x/crypto@v0.14.0
0.17.0
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/crypto@v0.13.0
0.17.0
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/crypto@v0.0.0-20191028145041-f83a4685e152
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
libssh@0.9.6-2ubuntu0.22.04.1
openssh@1:8.9p1-3ubuntu0.4
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/crypto@v0.1.0
0.17.0
1
deepflowce/mysql:8.0.313d7ae561cf60
paramiko@2.11.0
3.4.0
1
dellcloud/category:distributed02fc234353a9
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4
1
dellcloud/pages:1.04d2eb25b9225
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/crypto@v0.3.0
0.17.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.