StackRadar

CVE-2023-49582

Medium

Advisory

Published 26 Aug 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
3 of 3
affected packages

Apache Portable Runtime (APR): Unexpected lax shared memory permissions

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
aprdeb1.6.5-1ubuntu1, 1.7.0-8ubuntu0.22.04.1, 1.7.2-31.6.5-1ubuntu1.1, 1.7.0-8ubuntu0.22.04.2, 1.7.2-3+deb12u172
aprapk1.7.0-r2, 1.7.2-r0, 1.7.4-r01.7.5-r06
Apache Portable Runtime (APR)bitnami1.7.41.7.51
OSV records
ALPINE-CVE-2023-49582BIT-apr-2023-49582DEBIAN-CVE-2023-49582UBUNTU-CVE-2023-49582
Also known as
USN-7038-1

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

15,187
grrosdfir-infrastructureVerified publisher1.0.31 of 5See more

grr osdfir-infrastructure 1.0.3

1 of the 5 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

10,896
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

71,208
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

12,350
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
apr@1.7.2-3
1.7.2-3+deb12u1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

27,373
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

16,196
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

11,347
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

11,923
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

12,912
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1

Open the chart page →

9,167
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

8,169
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
apr@1.7.4-r0
1.7.5-r0

Open the chart page →

4,215
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

14,537
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

12,566
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

12,566
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

68,240
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

32,902
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

16,620
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
apr@1.7.4-r0
1.7.5-r0

Open the chart page →

2,449
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

13,510
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
apr@1.7.0-8ubuntu0.22.04.1
1.7.0-8ubuntu0.22.04.2

Open the chart page →

5,456
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

11,888
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

13,390
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

9,102
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1

Open the chart page →

18,756
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

11,199
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

28,858
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1

Open the chart page →

10,006
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

14,358
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-49582.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apr@1.7.2-3
1.7.2-3+deb12u1

Open the chart page →

10,001

Container images carrying it

79 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1
1
substratusai/verba:v0.4.0-baseURL261695be635eb
apr@1.7.2-3
1.7.2-3+deb12u1
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apr@1.7.2-3
1.7.2-3+deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1
1
teknas09/bird-pod:latest12a1fa85c4aa
apr@1.7.2-3
1.7.2-3+deb12u1
1
theradius/loggia:0.463ba348546ec
apr@1.7.2-3
1.7.2-3+deb12u1
1
thongngo3301/stakefish:latesta341af5976e3
apr@1.7.2-3
1.7.2-3+deb12u1
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
apr@1.7.4-r0
1.7.5-r0
1
vlebediantsev/notes-admin-front:latest007c6670ff48
apr@1.7.2-3
1.7.2-3+deb12u1
1
vlebediantsev/notes-project-front:latest945675fd2636
apr@1.7.2-3
1.7.2-3+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
apr@1.7.2-3
1.7.2-3+deb12u1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
apr@1.7.2-3
1.7.2-3+deb12u1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
apr@1.7.2-3
1.7.2-3+deb12u1
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
apr@1.7.2-3
1.7.2-3+deb12u1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
apr@1.7.2-3
1.7.2-3+deb12u1
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
apr@1.7.2-3
1.7.2-3+deb12u1
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
apr@1.7.2-r0
1.7.5-r0
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
apr@1.7.2-3
1.7.2-3+deb12u1
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
apr@1.7.2-3
1.7.2-3+deb12u1
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
apr@1.7.2-3
1.7.2-3+deb12u1
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
apr@1.7.4-r0
1.7.5-r0
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
apr@1.7.2-3
1.7.2-3+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
apr@1.7.2-3
1.7.2-3+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
apr@1.7.2-3
1.7.2-3+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
apr@1.7.2-3
1.7.2-3+deb12u1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apr@1.6.5-1ubuntu1
1.6.5-1ubuntu1.1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
apr@1.7.2-3
1.7.2-3+deb12u1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
apr@1.7.2-3
1.7.2-3+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.