StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,787 indexed, latest versions
Container images
1,762
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,787 indexed charts deploy, on 1,762 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,386
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

5,066
oesopsmxVerified publisher4.0.326 of 25See more

oes opsmx 4.0.32

6 of the 25 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.0.0-20231218163308-9d2ee975ef9f
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
openssh@9.1_p1-r2
0.0.0-20231218163308-9d2ee975ef9f
9.1_p1-r5
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.0.0-20231218163308-9d2ee975ef9f
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
openssh@1:7.2p2-4ubuntu2.10
0.0.0-20231218163308-9d2ee975ef9f
1:7.2p2-4ubuntu2.10+esm5
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9

Open the chart page →

107,899
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/crypto@v0.0.0-20220518034528-6f7dac969898
0.0.0-20231218163308-9d2ee975ef9f
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,757
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/crypto@v0.8.0
0.17.0

Open the chart page →

1,942
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,125
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,730
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

24,549
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,663
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/crypto@v0.0.0-20200323165209-0ec3e9974c59
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,502
sn-platformstreamnative1.11.445 of 9See more

sn-platform streamnative 1.11.44

5 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/crypto@v0.4.0
0.17.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

15,525
feedbacksystemthm-mni-iiVerified publisher0.47.14 of 10See more

feedbacksystem thm-mni-ii 0.47.1

4 of the 10 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/crypto@v0.12.0
0.17.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
openssh@9.1_p1-r1
0.0.0-20231218163308-9d2ee975ef9f
9.1_p1-r5
thmmniii/fbs-core:v1.27.15438517d9fc2
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/crypto@v0.1.0
0.17.0

Open the chart page →

28,579
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/crypto@v0.0.0-20200317142112-1b76d66859c6
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.0.0-20231218163308-9d2ee975ef9f
library/traefik:v2.57d5a6ae66572
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

9,257
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/crypto@v0.14.0
libssh@0.9.6-2ubuntu0.22.04.1
openssh@1:8.9p1-3ubuntu0.4
0.17.0
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

10,355
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/crypto@v0.11.0
0.17.0

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,245
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

3,178
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,033
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/crypto@v0.0.0-20220507011949-2cf3adece122
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,041
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

13,683
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
openssh@1:7.6p1-4ubuntu0.7
1:7.6p1-4ubuntu0.7+esm3

Open the chart page →

12,061
clearml-servingallegroaiVerified publisher1.6.23 of 9See more

clearml-serving allegroai 1.6.2

3 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/crypto@v0.4.0
0.17.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/crypto@v0.1.0
0.17.0

Open the chart page →

17,879
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/crypto@v0.0.0-20220307211146-efcb8507fb70
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/crypto@v0.0.0-20220307211146-efcb8507fb70
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,173
upcloud-csiankra-chartsVerified publisher0.4.02 of 8See more

upcloud-csi ankra-charts 0.4.0

2 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/crypto@v0.5.0
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

14,920
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
prom/prometheus:v2.37.98176adea328e
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

22,233
stash-enterpriseappscodeVerified publisher0.42.01 of 4See more

stash-enterprise appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,231
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,819
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.4

Open the chart page →

17,946
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,731
dltbrokerassist-iot-distributed-broker0.2.05 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

5 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

77,821
dltloggingassist-iot-logging-auditing0.2.05 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

5 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

77,802
deployautoml0.1.01 of 3See more

deploy automl 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
paramiko@2.11.0
3.4.0

Open the chart page →

2,947
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,298
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,729
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/crypto@v0.0.0-20200109152110-61a87790db17
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,814
chirpstackbeeinventor0.1.101 of 5See more

chirpstack beeinventor 0.1.10

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/crypto@v0.0.0-20200709230013-948cd5f35899
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,807
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/crypto@v0.0.0-20220516162934-403b01795ae8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,602
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

13,199
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,595
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

2,900
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,830
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

2,042
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,663
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

84,678
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

84,678

Container images carrying it

1,762 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
oxfordsemantic/rdfox:5.6db17910eb855
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/crypto@v0.10.0
0.17.0
1
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/crypto@v0.9.0
0.17.0
1
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1
phntom/goalert:0.0.298ca4df55499b
golang.org/x/crypto@v0.16.0
0.17.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/crypto@v0.14.0
libssh@0.9.6-2ubuntu0.22.04.1
0.17.0
0.9.6-2ubuntu0.22.04.2
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/crypto@v0.0.0-20220314234659-1baeb1ce4c0b
0.0.0-20231218163308-9d2ee975ef9f
1
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/crypto@v0.16.0
0.17.0
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/crypto@v0.6.0
0.17.0
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
libssh@0.9.0-4.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
golang.org/x/crypto@v0.6.0
0.17.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8
1
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/crypto@v0.8.0
0.17.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/crypto@v0.7.0
0.17.0
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/crypto@v0.0.0-20200420201142-3c4aac89819a
0.0.0-20231218163308-9d2ee975ef9f
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
project2team4/react:latest3ff031a08887
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.0.0-20231218163308-9d2ee975ef9f
1
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
1
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/crypto@v0.8.0
0.17.0
1
prom/prometheus:v2.18.15880ec936055
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.0.0-20231218163308-9d2ee975ef9f
1
prom/prometheus:v2.48.0b440bc0e8aa5
golang.org/x/crypto@v0.14.0
0.17.0
1
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.0.0-20231218163308-9d2ee975ef9f
1
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
1
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.0.0-20231218163308-9d2ee975ef9f
1
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
paramiko@2.7.1
3.4.0
1
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
1
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/crypto@v0.8.0
0.17.0
1
psorab/elibrary:latest53b68896c4ce
libssh@0.9.3-2ubuntu2.2
openssh@1:8.2p1-4ubuntu0.7
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
paramiko@2.11.0
3.4.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/crypto@v0.0.0-20200403201458-baeed622b8d8
0.0.0-20231218163308-9d2ee975ef9f
1
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
qumine/minecraft-server:v0.1.15c0b650d51132
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/crypto@v0.0.0-20210506145944-38f3c27a63bf
0.0.0-20231218163308-9d2ee975ef9f
1
rabeh/apibootspring:1.0941007b6946e
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.