StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,640
of 17,790 indexed, latest versions
Container images
1,764
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,640 of 17,790 indexed charts deploy, on 1,764 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,388
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,640 by stars
ChartLatestAffected imagesRadar Score
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
openssh@1:6.6p1-2ubuntu2.13
no fix listed

Open the chart page →

30,183
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
libssh@0.9.3-2ubuntu2.1
openssh@1:8.2p1-4ubuntu0.1
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10

Open the chart page →

12,550
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,876
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,828
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,439
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,031
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,290
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,941
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

6,514
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,602
capsule-rancher-addonclastixVerified publisher0.1.13 of 5See more

capsule-rancher-addon clastix 0.1.1

3 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/crypto@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/crypto@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

7,126
kamajiclastixVerified publisher0.0.0+latest1 of 4See more

kamaji clastix 0.0.0+latest

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,652
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,082
vcloud-csiclastixVerified publisher1.6.01 of 5See more

vcloud-csi clastix 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,413
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
curlimages/curl:7.87.0f7f265d5c64e
libssh2@1.10.0-r2
1.11.0-r0
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

21,034
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

18,040
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

27,454
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
openssh@1:6.6p1-2ubuntu2
no fix listed

Open the chart page →

36,878
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

34,027
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

23,697
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

11,827
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/crypto@v0.11.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8

Open the chart page →

25,513
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9

Open the chart page →

25,807
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/crypto@v0.0.0-20220321153916-2c7772ba3064
paramiko@2.10.3
0.0.0-20231218163308-9d2ee975ef9f
3.4.0

Open the chart page →

6,704
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
openssh@9.0_p1-r1
paramiko@2.11.0
0.0.0-20231218163308-9d2ee975ef9f
9.0_p1-r5
3.4.0

Open the chart page →

6,930
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

29,602
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

18,374
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0

Open the chart page →

12,501
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0

Open the chart page →

12,197
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
libssh@0.9.3-2ubuntu2.2
paramiko@2.8.0
0.9.3-2ubuntu2.4
3.4.0

Open the chart page →

11,636
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,143
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/crypto@v0.12.0
0.17.0

Open the chart page →

5,603
galaxy-depscloudve1.1.12 of 7See more

galaxy-deps cloudve 1.1.1

2 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,581
galaxykubemancloudve2.10.12 of 7See more

galaxykubeman cloudve 2.10.1

2 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
libssh@0.9.3-2ubuntu2.2
paramiko@2.11.0
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
3.4.0
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/crypto@v0.0.0-20190923035154-9ee001bba392
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,134
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
paramiko@1.10.1-1git1ubuntu0.1
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
paramiko@1.10.1-1git1ubuntu0.1
no fix listed

Open the chart page →

70,945
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

14,304
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,853
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,204
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
golang.org/x/crypto@v0.5.0
0.17.0

Open the chart page →

8,072
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,203
door-agentcnoVerified publisher3.0.153 of 15See more

door-agent cno 3.0.15

3 of the 15 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/crypto@v0.13.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/crypto@v0.0.0-20220314234659-1baeb1ce4c0b
0.0.0-20231218163308-9d2ee975ef9f
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

19,454
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,234
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,581
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,544
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,915
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libssh@0.9.6-3.el8
paramiko@2.11.0
0:0.9.6-13.el8_9
3.4.0

Open the chart page →

5,959
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

3,181
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,218
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,417

Container images carrying it

1,764 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/crypto@v0.10.0
0.17.0
1
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/crypto@v0.10.0
0.17.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/crypto@v0.0.0-20220321153916-2c7772ba3064
paramiko@2.10.3
0.0.0-20231218163308-9d2ee975ef9f
3.4.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/crypto@v0.0.0-20220924013350-4ba4fb4dd9e7
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/crypto@v0.0.0-20220924013350-4ba4fb4dd9e7
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/crypto@v0.6.0
0.17.0
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/crypto@v0.14.0
0.17.0
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/crypto@v0.6.0
0.17.0
1
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/crypto@v0.0.0-20220924013350-4ba4fb4dd9e7
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/crypto@v0.6.0
0.17.0
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/crypto@v0.16.0
0.17.0
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/crypto@v0.4.0
0.17.0
1
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/crypto@v0.8.0
0.17.0
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9
1
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/minio/directpv:v4.0.84560083eb77d
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/crypto@v0.1.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
golang.org/x/crypto@v0.13.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.