StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,638
of 17,790 indexed, latest versions
Container images
1,761
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,638 of 17,790 indexed charts deploy, on 1,761 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,385
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,638 by stars
ChartLatestAffected imagesRadar Score
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
golang.org/x/crypto@v0.15.0
0.17.0

Open the chart page →

4,226
alertmanagerprometheus-worawutchan0.3.01 of 1See more

alertmanager prometheus-worawutchan 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,305
prometheus-blackbox-exporterprometheus-worawutchan4.10.11 of 1See more

prometheus-blackbox-exporter prometheus-worawutchan 4.10.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,250
prometheus-node-exporterprometheus-worawutchan1.12.01 of 1See more

prometheus-node-exporter prometheus-worawutchan 1.12.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,188
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,724
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,510
kspanpuckpuck0.2.41 of 1See more

kspan puckpuck 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,681
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
libssh2@1.10.0-r4
openssh@9.3_p2-r0
1.11.0-r0
9.3_p2-r1

Open the chart page →

4,214
cdmswebapppyalive-cdmswebappVerified publisher0.1.02 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0
sarwansharma/minio:v359d1da9385d1
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,667
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,526
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

12,652
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

11,942
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

18,197
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,010
pagesranjinigogga1.0.01 of 3See more

pages ranjinigogga 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,233
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,738
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
oxfordsemantic/rdfox-init:5.6baf570ff968d
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

12,878
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

15,583
pagesrebecca-pages1.0.01 of 3See more

pages rebecca-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,233
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9

Open the chart page →

12,248
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

15,290
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

15,290
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
libssh@0.9.0-4.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libssh@0.9.6-4.el8_6
0:0.9.6-13.el8_9

Open the chart page →

16,060
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

29,226
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
golang.org/x/crypto@v0.0.0-20190426145343-a29dc8fdc734
0.0.0-20231218163308-9d2ee975ef9f
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

25,739
resource-manager-operatorresource-manager-operator0.1.01 of 1See more

resource-manager-operator resource-manager-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,623
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,490
backup-maker-controllerriotkit-org0.1.21 of 1See more

backup-maker-controller riotkit-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,575
rke2-calicorke2-charts3.18.1-1011 of 1See more

rke2-calico rke2-charts 3.18.1-101

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,250
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,942
yopassrlex0.8.01 of 2See more

yopass rlex 0.8.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jhaals/yopass:11.15.16bca8d5a4914
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

1,095
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

4,039
pagesroccohiggins-pages1.0.01 of 3See more

pages roccohiggins-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,233
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,051
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

5,422
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

2,022
mailserverrock8sVerified publisher0.1.21 of 1See more

mailserver rock8s 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

1,946
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,468
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
calicoromholdings0.1.13 of 4See more

calico romholdings 0.1.1

3 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,073
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.011 of 28See more

devtron-enterprise romholdings 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercdromholdings0.10.22 of 2See more

devtron-in-clustercd romholdings 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
devtron-operatorromholdings0.23.36 of 11See more

devtron-operator romholdings 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

31,447
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackromholdings19.3.02 of 6See more

kube-prometheus-stack romholdings 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435

Container images carrying it

1,761 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0
3
codeurjc/planner:v1.0800cf520c245
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
3
dpage/pgadmin4:6.12781369df9994
paramiko@2.11.0
3.4.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/crypto@v0.2.0
openssh@9.3_p1-r3
0.17.0
9.3_p2-r1
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
3
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.0.0-20231218163308-9d2ee975ef9f
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/crypto@v0.16.0
0.17.0
3
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f
3
xenondb/percona:5.7.330e26872a2b67
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/crypto@v0.14.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/crypto@v0.8.0
0.17.0
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.17.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/crypto@v0.1.0
0.17.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.17.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/crypto@v0.0.0-20190923035154-9ee001bba392
0.0.0-20231218163308-9d2ee975ef9f
3
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/crypto@v0.0.0-20220131195533-30dcbda58838
0.0.0-20231218163308-9d2ee975ef9f
2
apache/superset:dockerizeafe59523a6c8
golang.org/x/crypto@v0.9.0
0.17.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.