StackRadar

CVE-2023-52428

High

Advisory

Published 11 Feb 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
137
deployed by those charts
Fix available
1 of 1
affected package

Denial of Service in Connect2id Nimbus JOSE+JWT

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 137 images.

Affected packageAffected versionsFixed inImages
nimbus-jose-jwtmaven3.1.2, 3.9, 4.41.1, 4.41.2+29 more9.37.2137
OSV records
GHSA-gvpg-vgmx-xg6w

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

6,556
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
nimbus-jose-jwt@9.24.4
9.37.2

Open the chart page →

2,503
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

3,812
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

5,357
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
nimbus-jose-jwt@4.41.1
9.37.2
dbanda/spark:2.4.6d0e6367876ae
nimbus-jose-jwt@4.41.1
9.37.2

Open the chart page →

13,738
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

12,111
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
nimbus-jose-jwt@9.19
9.37.2

Open the chart page →

8,636
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

7,930
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
nimbus-jose-jwt@9.23
9.37.2

Open the chart page →

27,267
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
nimbus-jose-jwt@9.8.1
9.37.2
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

8,698
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

7,166
hdfsdmwm-bigdataVerified publisher1.0.11 of 2See more

hdfs dmwm-bigdata 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
gradiant/hdfs:3.2.2e3bf364fe713
nimbus-jose-jwt@7.9
9.37.2

Open the chart page →

7,948
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
nimbus-jose-jwt@4.41.1
9.37.2

Open the chart page →

7,335
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/elasticsearch:8.15.0310b9fc03b06
nimbus-jose-jwt@9.23
9.37.2

Open the chart page →

13,521
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
nimbus-jose-jwt@7.9
9.37.2

Open the chart page →

8,198
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.6.0f40a542832c4
nimbus-jose-jwt@9.22
9.37.2

Open the chart page →

14,566
vrijbrpvrijbrpVerified publisher0.1.51 of 5See more

vrijbrp vrijbrp 0.1.5

1 of the 5 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
nimbus-jose-jwt@9.22
9.37.2

Open the chart page →

8,811
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
nimbus-jose-jwt@7.9
9.37.2

Open the chart page →

7,740
soarv113assist-iot-cybersecurity-monitoring-soar0.1.32 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

2 of the 5 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
nimbus-jose-jwt@8.6
9.37.2
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

17,896
hadoopcloudnativeapp1.1.01 of 1See more

hadoop cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
nimbus-jose-jwt@3.9
9.37.2

Open the chart page →

5,772
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

38,346
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
nimbus-jose-jwt@6.5.1
9.37.2

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
nimbus-jose-jwt@8.20
9.37.2

Open the chart page →

6,531
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
nimbus-jose-jwt@9.24.4
9.37.2

Open the chart page →

5,291
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
nimbus-jose-jwt@9.31
9.37.2

Open the chart page →

15,562
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
nimbus-jose-jwt@4.41.1
9.37.2

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
nimbus-jose-jwt@4.41.1
9.37.2

Open the chart page →

4,679
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

17,284
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

12,019
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
nimbus-jose-jwt@8.14.1
9.37.2

Open the chart page →

7,710
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
nimbus-jose-jwt@3.9
9.37.2

Open the chart page →

5,772
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
nimbus-jose-jwt@9.23
9.37.2

Open the chart page →

37,373
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

31,844
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
nimbus-jose-jwt@8.20
9.37.2

Open the chart page →

4,621
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
nimbus-jose-jwt@9.10.1
9.37.2

Open the chart page →

3,958
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

6,045
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
nimbus-jose-jwt@7.1
9.37.2
seldonio/cluster-manager:0.2.729e362bb1ba2
nimbus-jose-jwt@7.1
9.37.2

Open the chart page →

13,798
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
nimbus-jose-jwt@7.9
9.37.2

Open the chart page →

13,486
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
nimbus-jose-jwt@9.8.1
9.37.2

Open the chart page →

7,835
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
nimbus-jose-jwt@9.31
9.37.2

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
nimbus-jose-jwt@9.31
9.37.2

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
nimbus-jose-jwt@9.31
9.37.2

Open the chart page →

2,853
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
nimbus-jose-jwt@9.31
9.37.2

Open the chart page →

2,221
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
aktosecurity/akto-api-protection:localbcd7382c9c1b
nimbus-jose-jwt@9.15.2
9.37.2

Open the chart page →

11,285
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
nimbus-jose-jwt@9.15.2
9.37.2

Open the chart page →

4,880
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
nimbus-jose-jwt@9.31
9.37.2
hazelcast/management-center:5.3.2f9d34300d330
nimbus-jose-jwt@9.30.2
9.37.2

Open the chart page →

28,131
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
nimbus-jose-jwt@8.14.1
9.37.2

Open the chart page →

5,277
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
nimbus-jose-jwt@9.31
9.37.2

Open the chart page →

14,728
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
nimbus-jose-jwt@9.23
9.37.2

Open the chart page →

9,722
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-52428.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
nimbus-jose-jwt@3.1.2
9.37.2

Open the chart page →

7,226

Container images carrying it

137 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
reportportal/service-authorization:5.7.09e73114dbd15
nimbus-jose-jwt@9.21
9.37.2
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
nimbus-jose-jwt@9.14
9.37.2
1
seldonio/apife:0.2.7ba81b17f00eb
nimbus-jose-jwt@7.1
9.37.2
1
seldonio/apife:0.3.1eea0d3f578ca
nimbus-jose-jwt@7.3
9.37.2
1
seldonio/cluster-manager:0.2.729e362bb1ba2
nimbus-jose-jwt@7.1
9.37.2
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
nimbus-jose-jwt@7.9
9.37.2
1
sslhep/hive-metastore:3.1.39e80af083079
nimbus-jose-jwt@4.41.1
9.37.2
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
nimbus-jose-jwt@9.31
9.37.2
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
nimbus-jose-jwt@9.24.1
9.37.2
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
nimbus-jose-jwt@9.24.1
9.37.2
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
nimbus-jose-jwt@9.24.1
9.37.2
1
thingsboard/tb-node:3.4.1645f43b688f7
nimbus-jose-jwt@9.22
9.37.2
1
thingsboard/tb-node:3.6.0f40a542832c4
nimbus-jose-jwt@9.22
9.37.2
1
trinodb/trino:45038c6f24ab1a4
nimbus-jose-jwt@9.8.1
9.37.2
1
trinodb/trino:405ee80ab5eeab2
nimbus-jose-jwt@9.14
9.37.2
1
vitalii1992/account-service:latest0e694d94551d
nimbus-jose-jwt@9.31
9.37.2
1
vitalii1992/analytics-service:latest8e798836ecea
nimbus-jose-jwt@9.31
9.37.2
1
vitalii1992/api-gateway-service:latestaabe6ac39356
nimbus-jose-jwt@9.31
9.37.2
1
vitalii1992/order-service:latest07c4a8833ce4
nimbus-jose-jwt@9.31
9.37.2
1
vlebediantsev/logic-ms:latestdf8bf38c535b
nimbus-jose-jwt@9.22
9.37.2
1
vlebediantsev/registration-ms-final:latest427af418b75e
nimbus-jose-jwt@9.22
9.37.2
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
nimbus-jose-jwt@9.22
9.37.2
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
nimbus-jose-jwt@9.22
9.37.2
1
wistefan/mvf:lateste0887302b2d8
nimbus-jose-jwt@9.9
9.37.2
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
nimbus-jose-jwt@6.5.1
9.37.2
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
nimbus-jose-jwt@9.8.1
9.37.2
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
nimbus-jose-jwt@4.41.1
9.37.2
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
nimbus-jose-jwt@9.8.1
9.37.2
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
nimbus-jose-jwt@9.8.1
9.37.2
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
nimbus-jose-jwt@9.8.1
9.37.2
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
nimbus-jose-jwt@9.8.1
9.37.2
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
nimbus-jose-jwt@7.9
9.37.2
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
nimbus-jose-jwt@9.8.1
9.37.2
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
nimbus-jose-jwt@9.31
9.37.2
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nimbus-jose-jwt@9.30.2
9.37.2
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
nimbus-jose-jwt@9.24.4
9.37.2
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
nimbus-jose-jwt@9.31
9.37.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.