StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,787 indexed, latest versions
Container images
1,762
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,787 indexed charts deploy, on 1,762 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,386
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
openssh@1:6.6p1-2ubuntu2.13
no fix listed

Open the chart page →

30,163
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
libssh@0.9.3-2ubuntu2.1
openssh@1:8.2p1-4ubuntu0.1
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10

Open the chart page →

12,531
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,869
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,821
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,439
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,031
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,290
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,934
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

6,487
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,595
capsule-rancher-addonclastixVerified publisher0.1.13 of 5See more

capsule-rancher-addon clastix 0.1.1

3 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/crypto@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/crypto@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

7,104
kamajiclastixVerified publisher0.0.0+latest1 of 4See more

kamaji clastix 0.0.0+latest

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,630
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,021
vcloud-csiclastixVerified publisher1.6.01 of 5See more

vcloud-csi clastix 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,386
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
curlimages/curl:7.87.0f7f265d5c64e
libssh2@1.10.0-r2
1.11.0-r0
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

20,936
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

18,040
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

27,434
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
openssh@1:6.6p1-2ubuntu2
no fix listed

Open the chart page →

36,866
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

34,014
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

23,683
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

11,831
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/crypto@v0.11.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8

Open the chart page →

25,152
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9

Open the chart page →

25,454
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/crypto@v0.0.0-20220321153916-2c7772ba3064
paramiko@2.10.3
0.0.0-20231218163308-9d2ee975ef9f
3.4.0

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
openssh@9.0_p1-r1
paramiko@2.11.0
0.0.0-20231218163308-9d2ee975ef9f
9.0_p1-r5
3.4.0

Open the chart page →

6,921
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

29,594
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

18,256
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0

Open the chart page →

12,505
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0

Open the chart page →

12,176
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0

Open the chart page →

11,640
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,136
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

5,552
galaxy-depscloudve1.1.12 of 7See more

galaxy-deps cloudve 1.1.1

2 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,543
galaxykubemancloudve2.10.12 of 7See more

galaxykubeman cloudve 2.10.1

2 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
libssh@0.9.3-2ubuntu2.2
paramiko@2.11.0
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
3.4.0
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/crypto@v0.0.0-20190923035154-9ee001bba392
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,117
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
paramiko@1.10.1-1git1ubuntu0.1
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
paramiko@1.10.1-1git1ubuntu0.1
no fix listed

Open the chart page →

70,968
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

14,285
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,853
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,994
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

7,521
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,203
door-agentcnoVerified publisher3.0.153 of 15See more

door-agent cno 3.0.15

3 of the 15 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/crypto@v0.13.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/crypto@v0.0.0-20220314234659-1baeb1ce4c0b
0.0.0-20231218163308-9d2ee975ef9f
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

19,380
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,234
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,572
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,544
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,906
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libssh@0.9.6-3.el8
paramiko@2.11.0
0:0.9.6-13.el8_9
3.4.0

Open the chart page →

5,958
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

3,181
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,408

Container images carrying it

1,762 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0
3
codeurjc/planner:v1.0800cf520c245
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
3
dpage/pgadmin4:6.12781369df9994
paramiko@2.11.0
3.4.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/crypto@v0.2.0
openssh@9.3_p1-r3
0.17.0
9.3_p2-r1
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
3
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.0.0-20231218163308-9d2ee975ef9f
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/crypto@v0.16.0
0.17.0
3
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f
3
xenondb/percona:5.7.330e26872a2b67
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/crypto@v0.14.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/crypto@v0.8.0
0.17.0
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.17.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/crypto@v0.1.0
0.17.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.17.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/crypto@v0.0.0-20190923035154-9ee001bba392
0.0.0-20231218163308-9d2ee975ef9f
3
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/crypto@v0.0.0-20220131195533-30dcbda58838
0.0.0-20231218163308-9d2ee975ef9f
2
apache/superset:dockerizeafe59523a6c8
golang.org/x/crypto@v0.9.0
0.17.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.