StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,787 indexed, latest versions
Container images
1,762
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,787 indexed charts deploy, on 1,762 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,386
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
devtron-enterprisedevtron48.0.011 of 28See more

devtron-enterprise devtron 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackdevtron19.3.02 of 6See more

kube-prometheus-stack devtron 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,507
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,580
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.011 of 28See more

devtron-enterprise devtron-labs 48.0.0

11 of the 28 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.36 of 11See more

devtron-operator devtron-labs 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

11,957
kube-prometheus-stackdevtron-labs19.3.02 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,645
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,435
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,507
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,233
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,806
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2

Open the chart page →

13,031
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/crypto@v0.1.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9

Open the chart page →

21,455
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,632
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,126
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,408
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,046
channelsdoubanVerified publisher1.1.21 of 1See more

channels douban 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
everpcpc/channels:latestb378d137ae8b
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,539
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
curlimages/curl:7.87.0f7f265d5c64e
libssh2@1.10.0-r2
1.11.0-r0
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2

Open the chart page →

24,975
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

3,660
prometheus-memcached-exporterdoubanVerified publisher0.1.31 of 1See more

prometheus-memcached-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,114
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

11,831
tencentcloud-info-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-info-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,325
drogue-cloud-coredrogue-iotVerified publisher0.7.112 of 22See more

drogue-cloud-core drogue-iot 0.7.11

2 of the 22 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
quay.io/keycloak/keycloak:20.0054ef67eb7da
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

55,988
drogue-cloud-examplesdrogue-iotVerified publisher0.7.115 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

5 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
golang.org/x/crypto@v0.0.0-20190911031432-227b76d455e7
libssh@0.9.6-2build1
0.0.0-20231218163308-9d2ee975ef9f
0.9.6-2ubuntu0.22.04.2
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/crypto@v0.14.0
0.17.0
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9

Open the chart page →

30,759
drogue-cloud-metricsdrogue-iotVerified publisher0.7.114 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

4 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

13,558
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

6,914
drone-kubernetes-secretsdroneVerified publisher0.1.41 of 1See more

drone-kubernetes-secrets drone 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,760
temporaldtrdnk-helm-chartsVerified publisher0.35.07 of 13See more

temporal dtrdnk-helm-charts 0.35.0

7 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/crypto@v0.14.0
0.17.0
temporalio/server:1.22.4c0a44c26397b
golang.org/x/crypto@v0.14.0
0.17.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

20,204
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
paramiko@2.11.0
3.4.0

Open the chart page →

1,362
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

2,413
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,679
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

19,820
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,141
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,801
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,179

Container images carrying it

1,762 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
libssh@0.9.6-10.el8_8
paramiko@2.12.0
0:0.9.6-13.el8_8
3.4.0
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
libssh@0.9.6-10.el8_8
paramiko@2.12.0
0:0.9.6-13.el8_8
3.4.0
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/crypto@v0.5.0
0.17.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f
2
curlimages/curl:8.4.04a3396ae573c
libssh2@1.10.0-r4
1.11.0-r0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
2
eqalpha/keydb:latest6537505c4235
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.4
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.4
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
2
governify/dashboard:lateste83a17ba5038
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/loki:2.5.0f9ef133793af
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f
2
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
2
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
2
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/crypto@v0.14.0
0.17.0
2
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/crypto@v0.0.0-20220817201139-bc19a97f63c8
0.0.0-20231218163308-9d2ee975ef9f
2
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/crypto@v0.14.0
0.17.0
2
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
2
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/crypto@v0.14.0
0.17.0
2
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/crypto@v0.14.0
0.17.0
2
inaccel/daemon:latest093e1ea90ab8
golang.org/x/crypto@v0.16.0
0.17.0
2
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.0.0-20231218163308-9d2ee975ef9f
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
2
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
2
istio/proxyv2:1.18.0757d28c24100
golang.org/x/crypto@v0.7.0
libssh@0.9.6-2ubuntu0.22.04.1
0.17.0
0.9.6-2ubuntu0.22.04.2
2
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
2
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/crypto@v0.0.0-20210920023735-84f357641f63
0.0.0-20231218163308-9d2ee975ef9f
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.