StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,787 indexed, latest versions
Container images
1,762
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,787 indexed charts deploy, on 1,762 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,386
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
devtron-enterprisedevtron48.0.011 of 28See more

devtron-enterprise devtron 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackdevtron19.3.02 of 6See more

kube-prometheus-stack devtron 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,507
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.011 of 28See more

devtron-enterprise devtron-labs 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.36 of 11See more

devtron-operator devtron-labs 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackdevtron-labs19.3.02 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,507
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,233
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,806
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2

Open the chart page →

13,031
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/crypto@v0.1.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9

Open the chart page →

21,455
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,632
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,126
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,408
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,046
channelsdoubanVerified publisher1.1.21 of 1See more

channels douban 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
everpcpc/channels:latestb378d137ae8b
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,539
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
curlimages/curl:7.87.0f7f265d5c64e
libssh2@1.10.0-r2
1.11.0-r0
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2

Open the chart page →

24,975
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

3,660
prometheus-memcached-exporterdoubanVerified publisher0.1.31 of 1See more

prometheus-memcached-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,114
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

11,831
tencentcloud-info-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-info-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,325
drogue-cloud-coredrogue-iotVerified publisher0.7.112 of 22See more

drogue-cloud-core drogue-iot 0.7.11

2 of the 22 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
quay.io/keycloak/keycloak:20.0054ef67eb7da
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

55,988
drogue-cloud-examplesdrogue-iotVerified publisher0.7.115 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

5 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
golang.org/x/crypto@v0.0.0-20190911031432-227b76d455e7
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/crypto@v0.14.0
0.17.0
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9

Open the chart page →

30,759
drogue-cloud-metricsdrogue-iotVerified publisher0.7.114 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

4 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

13,558
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

6,914
drone-kubernetes-secretsdroneVerified publisher0.1.41 of 1See more

drone-kubernetes-secrets drone 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,760
temporaldtrdnk-helm-chartsVerified publisher0.35.07 of 13See more

temporal dtrdnk-helm-charts 0.35.0

7 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/crypto@v0.14.0
0.17.0
temporalio/server:1.22.4c0a44c26397b
golang.org/x/crypto@v0.14.0
0.17.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

20,204
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
paramiko@2.11.0
3.4.0

Open the chart page →

1,362
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

2,413
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,679
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

19,820
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,141
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,801
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,179

Container images carrying it

1,762 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/crypto@v0.15.0
0.17.0
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/crypto@v0.3.0
0.17.0
1
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/crypto@v0.0.0-20200128174031-69ecbb4d6d5d
0.0.0-20231218163308-9d2ee975ef9f
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
dollarshaveclub/furan2:master14a257836529
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.0.0-20231218163308-9d2ee975ef9f
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/crypto@v0.10.0
0.17.0
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
openssh@1:8.2p1-4ubuntu0.13
1:8.2p1-4ubuntu0.fips.0.10
1
dpage/pgadmin4:7.537946e4f3e7b
paramiko@3.2.0
3.4.0
1
dpage/pgadmin4:4.22b1f00b8163cf
paramiko@2.7.1
3.4.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2
1
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/crypto@v0.0.0-20190621222207-cc06ce4a13d4
0.0.0-20231218163308-9d2ee975ef9f
1
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f
1
drpcorg/dshackle:0.54.08858fae1859d
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/crypto@v0.12.0
0.17.0
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
golang.org/x/crypto@v0.5.0
openssh@9.1_p1-r2
0.17.0
9.1_p1-r5
1
duck1123/cert-downloader:latest0e29f19fa67c
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
duck1123/lnd-fileserver:latest9d6fb247b714
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
golang.org/x/crypto@v0.14.0
0.17.0
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/crypto@v0.14.0
0.17.0
1
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/crypto@v0.0.0-20220817201139-bc19a97f63c8
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
paramiko@2.6.0
3.4.0
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1
engrmth/bnkr:2.1.06d8464e6f0e8
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/crypto@v0.0.0-20191219195013-becbf705a915
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
openssh@9.0_p1-r2
0.0.0-20231218163308-9d2ee975ef9f
9.0_p1-r5
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/crypto@v0.14.0
openssh@9.3_p2-r0
0.17.0
9.3_p2-r1
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/crypto@v0.9.0
0.17.0
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ethereum/client-go:v1.10.186d6d12a40465
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm5
1
ethereumoptimism/l2geth:0.5.315577036dc36d
golang.org/x/crypto@v0.0.0-20220307211146-efcb8507fb70
0.0.0-20231218163308-9d2ee975ef9f
1
ethersphere/onboarding-faucet:0.3.0513154aab230
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
1
ethpandaops/blob-me-baby:latestad26158420dd
golang.org/x/crypto@v0.14.0
0.17.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.