StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,787 indexed, latest versions
Container images
1,762
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,787 indexed charts deploy, on 1,762 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,386
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/crypto@v0.11.0
0.17.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/crypto@v0.8.0
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.17.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/crypto@v0.11.0
0.17.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/crypto@v0.8.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

7,740
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

22,713
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,547
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

13,387
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

2,246
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
openssh@1:6.6p1-2ubuntu2
no fix listed

Open the chart page →

41,455
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,527
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,861
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,806
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

27,486
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

4,989
lensoci-ai-incubations0.1.143 of 16See more

lens oci-ai-incubations 0.1.14

3 of the 16 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/crypto@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/crypto@v0.14.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

17,085
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,124
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

5,825
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

8,130
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,539
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

9,059
exposecontrollerolli-aiVerified publisher1.0.51 of 1See more

exposecontroller olli-ai 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,861
k8s-replicatorolli-aiVerified publisher1.3.01 of 1See more

k8s-replicator olli-ai 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,825
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8

Open the chart page →

18,666
one-green-coreone-green-coreVerified publisher0.0.73 of 8See more

one-green-core one-green-core 0.0.7

3 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
library/telegraf:1.20.428e98eece020
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

9,558
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

18,023
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
golang.org/x/crypto@v0.0.0-20200204104054-c9f3fb736b72
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,906
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,720
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm5
omecproject/onos-progran:1.0.05715e5648aa0
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

88,616
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

26,234
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,612
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
omecproject/c3po-hssdb:master-latest28a90cc26716
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

40,795
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

38,889
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
paramiko@2.6.0
3.4.0

Open the chart page →

12,631
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm5

Open the chart page →

93,965
volthaopencord2.14.01 of 2See more

voltha opencord 2.14.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,811
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

41,088
voltha-stackopencord2.14.01 of 4See more

voltha-stack opencord 2.14.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,539
federated-gatewayopenfaas0.1.01 of 1See more

federated-gateway openfaas 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

1,240
nats-connectoropenfaas0.3.21 of 1See more

nats-connector openfaas 0.3.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/openfaas/nats-connector:0.3.0315e57c0a8d8
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,471
probuilderopenfaas0.2.01 of 2See more

probuilder openfaas 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
moby/buildkit:v0.10.0c2aeafaed434
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,752
kruise-state-metricsopenkruise0.2.01 of 1See more

kruise-state-metrics openkruise 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
openkruise/kruise-state-metrics:v0.2.0a8108f771287
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,928
openldapopenldap0.1.12 of 2See more

openldap openldap 0.1.1

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
php-phpseclib@2.0.30-2
2.0.30-2+deb11u1
osixia/openldap:1.5.018742e9c449c
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,293
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
golang.org/x/crypto@v0.3.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/crypto@v0.5.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9

Open the chart page →

7,457
open-pdcopen-pdc0.1.01 of 3See more

open-pdc open-pdc 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

3,423
open-pubopen-pub0.1.01 of 3See more

open-pub open-pub 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

3,423
exporteropenshift1.0.471 of 3See more

exporter openshift 1.0.47

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.64 of 6See more

fsm openshift 0.1.8-ubi.6

4 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
libssh@0.9.6-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

16,554
opscruiseopenshift0.35.1003 of 11See more

opscruise openshift 0.35.100

3 of the 11 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:2.0.077e138f81a8e
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
grafana/promtail:2.0.05fd12edcc694
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,201
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi86 of 7See more

osm-edge openshift 1.2.1-ubi8

6 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
golang.org/x/crypto@v0.5.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
golang.org/x/crypto@v0.5.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
golang.org/x/crypto@v0.5.0
libssh@0.9.6-3.el8
0.17.0
0:0.9.6-13.el8_9
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

19,449

Container images carrying it

1,762 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4
79
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0
22
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5
11
codeurjc/weatherservice:v1.0b9e2f7234349
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
10
library/mongo:5.0.6-focal8e70544b6c76
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
10
codeurjc/server:v1.0310bea5b1ee7
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
8
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f
8
osixia/openldap:1.5.018742e9c449c
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.0.0-20231218163308-9d2ee975ef9f
7
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/crypto@v0.12.0
0.17.0
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.0.0-20231218163308-9d2ee975ef9f
6
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.0.0-20231218163308-9d2ee975ef9f
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
openssh@1:9.2p1-2+deb12u1
0.17.0
1:9.2p1-2+deb12u2
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.17.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
6
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.17.0
5
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
0.0.0-20231218163308-9d2ee975ef9f
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.0.0-20231218163308-9d2ee975ef9f
5
curlimages/curl:7.87.0:multiarch-7.87.0f7f265d5c64e
libssh2@1.10.0-r2
1.11.0-r0
4
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
4
grafana/loki:2.6.11ee60f980950
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm5
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm5
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
4
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
4
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
4
library/mongo:4.4.66efa05203990
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
4
mastercloudapps/planner:v1.2340a950b311b2
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2
4
mastercloudapps/server:v2.23f3d24dfe2686
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
4
mastercloudapps/weatherservice:v1.23de859d29c116
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.17.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/crypto@v0.13.0
0.17.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/crypto@v0.13.0
0.17.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/crypto@v0.13.0
0.17.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.17.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.0.0-20231218163308-9d2ee975ef9f
4
quay.io/strimzi/operator:0.37.052f376e64b9b
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/crypto@v0.14.0
0.17.0
3
ciscolabs/rtsp-client:latesta7b60ec88285
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.