StackRadar

CVE-2023-51775

Medium

Advisory

Published 29 Feb 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
47
of 17,781 indexed, latest versions
Container images
45
deployed by those charts
Fix available
1 of 1
affected package

jose4j denial of service via specifically crafted JWE

Carried by container images the latest versions of 47 of 17,781 indexed charts deploy, on 45 images.

Affected packageAffected versionsFixed inImages
jose4jmaven0.5.5, 0.6.3, 0.6.5, 0.7.0+9 more0.9.445
OSV records
GHSA-6qvw-249j-h44c

Charts affected

47 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
jose4j@0.7.9
0.9.4

Open the chart page →

7,713
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
jose4j@0.7.6
0.9.4

Open the chart page →

32,259
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
jose4j@0.9.3
0.9.4

Open the chart page →

6,675
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
jose4j@0.6.5
0.9.4

Open the chart page →

6,048
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
jose4j@0.9.3
0.9.4

Open the chart page →

7,930
guacamolehalkeye0.2.11 of 3See more

guacamole halkeye 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
guacamole/guacamole:1.1.0333a7f40c145
jose4j@0.5.5
0.9.4

Open the chart page →

4,839
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
jose4j@0.7.0
0.9.4

Open the chart page →

18,042
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
jose4j@0.9.3
0.9.4

Open the chart page →

14,566
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
jose4j@0.7.9
0.9.4

Open the chart page →

17,877
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jose4j@0.9.3
0.9.4

Open the chart page →

15,562
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
jose4j@0.7.11
0.9.4

Open the chart page →

37,373
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
jose4j@0.7.0
0.9.4

Open the chart page →

31,844
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
jose4j@0.7.12
0.9.4

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jose4j@0.6.5
0.9.4

Open the chart page →

24,930
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
jose4j@0.7.9
0.9.4

Open the chart page →

7,713
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
jose4j@0.9.3
0.9.4
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
jose4j@0.9.3
0.9.4

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
jose4j@0.7.11
0.9.4

Open the chart page →

13,352
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jose4j@0.7.8
0.9.4

Open the chart page →

5,958
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
jose4j@0.7.9
0.9.4

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
jose4j@0.7.9
0.9.4

Open the chart page →

7,963
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jose4j@0.6.5
0.9.4
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jose4j@0.7.2
0.9.4
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jose4j@0.6.5
0.9.4
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jose4j@0.7.2
0.9.4
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jose4j@0.7.2
0.9.4
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jose4j@0.7.2
0.9.4

Open the chart page →

58,857
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
jose4j@0.7.11
0.9.4

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
jose4j@0.7.11
0.9.4

Open the chart page →

6,915
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
guacamole/guacamole:1.3.0739cb6820ae8
jose4j@0.5.5
0.9.4

Open the chart page →

6,412
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
jose4j@0.7.7
0.9.4

Open the chart page →

2,887
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
jose4j@0.7.12
0.9.4

Open the chart page →

16,401
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
jose4j@0.7.9
0.9.4

Open the chart page →

20,650
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jose4j@0.7.9
0.9.4

Open the chart page →

2,653
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jose4j@0.7.9
0.9.4

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jose4j@0.7.9
0.9.4

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jose4j@0.7.9
0.9.4

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jose4j@0.7.9
0.9.4

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jose4j@0.7.9
0.9.4

Open the chart page →

19,226
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jose4j@0.7.6
0.9.4

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jose4j@0.7.6
0.9.4

Open the chart page →

15,675
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
jose4j@0.9.2
0.9.4

Open the chart page →

4,989
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
jose4j@0.9.3
0.9.4

Open the chart page →

9,005
apicurioone-acre-fundVerified publisher2.3.02 of 5See more

apicurio one-acre-fund 2.3.0

2 of the 5 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jose4j@0.9.2
0.9.4
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jose4j@0.9.2
0.9.4

Open the chart page →

18,667
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jose4j@0.9.3
0.9.4

Open the chart page →

5,269
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
jose4j@0.7.9
0.9.4

Open the chart page →

6,443
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jose4j@0.6.3
0.9.4

Open the chart page →

13,605
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jose4j@0.6.5
0.9.4

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jose4j@0.6.5
0.9.4

Open the chart page →

8,806
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jose4j@0.7.6
0.9.4

Open the chart page →

12,455
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jose4j@0.7.9
0.9.4

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jose4j@0.7.2
0.9.4

Open the chart page →

28,605
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-51775.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jose4j@0.7.11
0.9.4

Open the chart page →

6,016

Container images carrying it

45 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
solsson/kafka:latest41e5d8f6f290
jose4j@0.7.9
0.9.4
5
library/solr:8.11.18c5f7881cebb
jose4j@0.6.5
0.9.4
3
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
jose4j@0.7.9
0.9.4
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
jose4j@0.7.11
0.9.4
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
jose4j@0.7.9
0.9.4
2
apache/drill:1.21.11f96558fd292
jose4j@0.7.9
0.9.4
1
apache/druid:29.0.10cef139b6bf1
jose4j@0.9.3
0.9.4
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
jose4j@0.9.3
0.9.4
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
jose4j@0.7.6
0.9.4
1
apachepulsar/pulsar:2.9.0d056c89b7131
jose4j@0.7.6
0.9.4
1
apachepulsar/pulsar:2.8.2d538416d5afe
jose4j@0.7.6
0.9.4
1
apache/skywalking-oap-server:9.2.0133d35d2c263
jose4j@0.7.12
0.9.4
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
jose4j@0.7.0
0.9.4
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
jose4j@0.7.9
0.9.4
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jose4j@0.7.6
0.9.4
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jose4j@0.9.2
0.9.4
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jose4j@0.9.2
0.9.4
1
assistiot/identity-manager_kc:latest0df4b4fa899a
jose4j@0.7.11
0.9.4
1
atlassian/confluence-server:7.10.03b9222ab32ef
jose4j@0.6.3
0.9.4
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
jose4j@0.9.3
0.9.4
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
jose4j@0.7.9
0.9.4
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
jose4j@0.7.11
0.9.4
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jose4j@0.6.5
0.9.4
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jose4j@0.7.2
0.9.4
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jose4j@0.7.8
0.9.4
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jose4j@0.9.3
0.9.4
1
confluentinc/cp-kafka:7.5.1dc9b972db002
jose4j@0.9.3
0.9.4
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jose4j@0.6.5
0.9.4
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jose4j@0.7.2
0.9.4
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jose4j@0.9.3
0.9.4
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jose4j@0.7.2
0.9.4
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jose4j@0.7.2
0.9.4
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
jose4j@0.9.3
0.9.4
1
guacamole/guacamole:1.1.0333a7f40c145
jose4j@0.5.5
0.9.4
1
guacamole/guacamole:1.3.0739cb6820ae8
jose4j@0.5.5
0.9.4
1
hivemq/hivemq4:dns-4.5.144d194450d48e
jose4j@0.7.9
0.9.4
1
library/solr:8.7.0d124efd81fbb
jose4j@0.6.5
0.9.4
1
ncsa/datawolf:4.7.0af6649d59150
jose4j@0.9.2
0.9.4
1
openhab/openhab:3.2.0d0aa4af452c1
jose4j@0.7.7
0.9.4
1
treskon/portrait:DEV-latest88e813f22347
jose4j@0.7.0
0.9.4
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
jose4j@0.7.12
0.9.4
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
jose4j@0.9.3
0.9.4
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jose4j@0.7.2
0.9.4
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
jose4j@0.7.9
0.9.4
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jose4j@0.7.11
0.9.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.