CVE-2023-48795
MediumAdvisory
Published 18 Dec 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.933
- 100th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,639
- of 17,803 indexed, latest versions
- Container images
- 1,763
- deployed by those charts
- Fix available
- 8 of 10
- affected packages
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Carried by container images the latest versions of 1,639 of 17,803 indexed charts deploy, on 1,763 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more | 0.0.0-20231218163308-9d2ee975ef9f, 0.17.0 | 1,387 |
| libsshdeb | 0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more | 0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1 | 243 |
| libsshrpm | 0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more | 0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9 | 156 |
| opensshdeb | 1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more | 1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more | 101 |
| paramikopypi | 2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more | 3.4.0 | 58 |
| opensshapk | 9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more | 9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r1 | 22 |
| libssh2apk | 1.10.0-r2, 1.10.0-r3, 1.10.0-r4 | 1.11.0-r0 | 10 |
| paramikodeb | 1.10.1-1git1ubuntu0.1 | no fix listed | 2 |
| dropbeardeb | 2022.83-4 | no fix listed | 1 |
| php-phpseclibdeb | 2.0.14-1, 2.0.30-2 | 2.0.30-2+deb11u1, 2.0.30-2~deb10u2 | 2 |
- OSV records
- ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
- Also known as
- GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1
Charts affected
1,639 by stars
Container images carrying it
1,763 by charts deploying them
A fixed version is listed for 8 of the 10 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.gitlab.com/ | 4e7faf6f8d5f | openssh | 9.0_p1-r5 | 1 |
| registry.k8s.io/ | 026f63d9ed42 | golang.org/ | 0.17.0 | 1 |
| registry.k8s.io/ | af7e3857d877 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |
| registry.k8s.io/ | fd9722fd02e3 | openssh | 1:9.2p1-2+deb12u2 | 1 |
| registry.k8s.io/ | f6902791fb9a | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |
| registry.k8s.io/ | 66ce7d460e53 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |
| registry.k8s.io/ | 0684e23172d9 | golang.org/ | 0.17.0 | 1 |
| registry.k8s.io/ | 3ae5620a33bb | golang.org/ | 0.17.0 | 1 |
| registry.k8s.io/ | 9330c53feca7 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |
| registry.k8s.io/ | 5658d0011a41 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |
| registry.k8s.io/ | ec5732e28f15 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |
| registry.k8s.io/ | e6a43c83ab16 | golang.org/ | 0.17.0 | 1 |
| registry.k8s.io/ | 3ce0fdba4d8e | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f | 1 |