StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,640
of 17,790 indexed, latest versions
Container images
1,764
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,640 of 17,790 indexed charts deploy, on 1,764 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,388
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,640 by stars
ChartLatestAffected imagesRadar Score
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

4,456
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

4,773
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

8,767
operatingkusionstackVerified publisher0.5.11 of 1See more

operating kusionstack 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

1,881
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,539
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8

Open the chart page →

4,098
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,543
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

26,377
pageslatif-pages1.0.01 of 3See more

pages latif-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,242
pageslavanya-pages1.0.01 of 3See more

pages lavanya-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,242
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.54 of 6See more

prometheus lectures-k8sinfra 15.8.5

4 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,198
prometheusleechistest11.6.03 of 6See more

prometheus leechistest 11.6.0

3 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
0.0.0-20231218163308-9d2ee975ef9f
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,491
kube-benchlemontechVerified publisher0.1.01 of 1See more

kube-bench lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.9c329d73fea58
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,632
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,280
kltlifecycle-toolkitOfficialVerified publisher0.2.62 of 4See more

klt lifecycle-toolkit 0.2.6

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
golang.org/x/crypto@v0.12.0
0.17.0
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

4,680
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,459
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/crypto@v0.0.0-20220131195533-30dcbda58838
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/crypto@v0.0.0-20220131195533-30dcbda58838
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,777
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

10,780
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/crypto@v0.0.0-20210314154223-e6e6c4f2bb5b
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,135
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,242
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

4,911
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

2,108
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-auth-go:latest6597b26959d2
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

5,905
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,519
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

3,234
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/crypto@v0.0.0-20200128174031-69ecbb4d6d5d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

9,888
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,094
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

2,453
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,119
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

3,234
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

5,101
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.102 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.17.0
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,951
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/crypto@v0.5.0
0.17.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

5,786
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.17.0
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/crypto@v0.1.0
0.17.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/crypto@v0.1.0
0.17.0

Open the chart page →

8,235
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,993
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,501
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

9,062
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,508
apica-ascentlogiqai2.0.44 of 19See more

apica-ascent logiqai 2.0.4

4 of the 19 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.0.0-20231218163308-9d2ee975ef9f
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

23,689
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,349
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

17,858
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

9,347
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,773
kube-benchm9sweeperVerified publisher1.6.01 of 1See more

kube-bench m9sweeper 1.6.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.176672264accce
golang.org/x/crypto@v0.4.0
0.17.0

Open the chart page →

1,400
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
kubesec/kubesec:v2.13.0c0f3b0673578
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

9,805
magistralamagistrala-devopsVerified publisher0.16.23 of 42See more

magistrala magistrala-devops 0.16.2

3 of the 42 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
natsio/nats-box:0.14.31cc420186664
golang.org/x/crypto@v0.9.0
0.17.0
timescale/timescaledb:latest-pg12645fd9e92d76
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

24,537
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

3,713

Container images carrying it

1,764 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/crypto@v0.0.0-20211115234514-b4de73f9ece8
0.0.0-20231218163308-9d2ee975ef9f
1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
mattermost/calls-offloader:v0.9.0b440b282599e
golang.org/x/crypto@v0.16.0
0.17.0
1
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
1
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
1
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/crypto@v0.5.0
0.17.0
1
mediagis/nominatim:3.7c15e941485ef
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
golang.org/x/crypto@v0.11.0
0.17.0
1
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/crypto@v0.0.0-20181029021203-45a5f77698d3
0.0.0-20231218163308-9d2ee975ef9f
1
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
1
milvusdb/milvus:v2.2.13a3a55e1c1497
golang.org/x/crypto@v0.9.0
libssh@0.9.3-2ubuntu2.2
0.17.0
0.9.3-2ubuntu2.4
1
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
1
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
minio/kes:v0.22.255f3aef5803e
golang.org/x/crypto@v0.0.0-20211209193657-4570a0811e8b
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
golang.org/x/crypto@v0.4.0
0.17.0
1
minio/mc:RELEASE.2020-04-25T00-43-23Z1806872732e1
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.0.0-20231218163308-9d2ee975ef9f
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.0.0-20231218163308-9d2ee975ef9f
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
golang.org/x/crypto@v0.6.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
golang.org/x/crypto@v0.0.0-20211209193657-4570a0811e8b
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
golang.org/x/crypto@v0.7.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/crypto@v0.0.0-20191117063200-497ca9f6d64f
0.0.0-20231218163308-9d2ee975ef9f
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
golang.org/x/crypto@v0.1.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/crypto@v0.5.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
1
minio/operator:v5.0.9170b154d2c61
golang.org/x/crypto@v0.11.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8
1
minio/operator:v4.1.02adc5be088f5
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
1
moby/buildkit:v0.10.0c2aeafaed434
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f
1
monitoror/monitoror:44b88edcf51ff
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.