CVE-2023-5528
HighAdvisory
Published 14 Nov 2023In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.8
- base score, highest
- EPSS
- 0.036
- 89th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 175
- of 17,781 indexed, latest versions
- Container images
- 152
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Kubernetes Improper Input Validation vulnerability
Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 152 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| k8s.io/ | v0.0.0-20240417172702-7c48c2bd72b9, v0.0.0-20240514104202-6911225c3f74, v0.0.0-20240611201126-f25b321b9ae4, v0.0.0-20240611201706-062798d53d83+82 more | 1.25.16, 1.26.11, 1.27.8, 1.28.4 | 152 |
- OSV records
- GHSA-hq6q-c2x6-hmch
- Also known as
- GO-2023-2341
Charts affected
175 by stars
Container images carrying it
152 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| clastix/ | 22918a06c253 | k8s.io/ | 1.25.16 | 6 |
| quay.io/ | 2ad610626658 | k8s.io/ | 1.25.16 | 6 |
| quay.io/ | e6df72478956 | k8s.io/ | 1.25.16 | 5 |
| argoproj/ | 830e86cacefd | k8s.io/ | 1.25.16 | 3 |
| groundnuty/ | c14d7271e401 | k8s.io/ | 1.25.16 | 3 |
| quay.io/ | 6545dac92173 | k8s.io/ | 1.25.16 | 3 |
| quay.io/ | 2b6db27eaf3d | k8s.io/ | 1.25.16 | 3 |
| quay.io/ | bc4aa22272ef | k8s.io/ | 1.25.16 | 3 |
| quay.io/ | 4c3b91bebd3d | k8s.io/ | 1.25.16 | 3 |
| quay.io/ | f296c2ec5db7 | k8s.io/ | 1.27.8 | 3 |
| quay.io/ | eec0305b594c | k8s.io/ | 1.25.16 | 3 |
| quay.io/ | 1b33357b3595 | k8s.io/ | 1.26.11 | 3 |
| registry.k8s.io/ | 99b37df34bc4 | k8s.io/ | 1.25.16 | 3 |
| bitnamilegacy/ | a0a972324d93 | k8s.io/ | 1.26.11 | 2 |
| csiplugin/ | 0766163dc046 | k8s.io/ | 1.25.16 | 2 |
| iomesh/ | f13deacac3f4 | k8s.io/ | 1.25.16 | 2 |
| k0sproject/ | f04635825d51 | k8s.io/ | 1.26.11 | 2 |
| lachlanevenson/ | af5cea3f2e40 | k8s.io/ | 1.25.16 | 2 |
| ghcr.io/ | 82d0b161161d | k8s.io/ | 1.25.16 | 2 |
| ghcr.io/ | c137478627cc | k8s.io/ | 1.25.16 | 2 |
| public.ecr.aws/ | 1564359e1e0e | k8s.io/ | 1.26.11 | 2 |
| quay.io/ | f7f8228f17cc | k8s.io/ | 1.25.16 | 2 |
| quay.io/ | 00406ccb1fa0 | k8s.io/ | 1.26.11 | 2 |
| quay.io/ | 382fca2054c9 | k8s.io/ | 1.25.16 | 2 |
| registry.k8s.io/ | 99e1ed9fbc8a | k8s.io/ | 1.26.11 | 2 |
| registry.k8s.io/ | 40adecbe3a40 | k8s.io/ | 1.26.11 | 2 |
| registry.k8s.io/ | 74a5cf9cfa9f | k8s.io/ | 1.25.16 | 2 |
| registry.k8s.io/ | 63d5e04551ec | k8s.io/ | 1.25.16 | 2 |
| airbyte/ | 98d2c39d512e | k8s.io/ | 1.25.16 | 1 |
| alpine/ | 21b24e6bf801 | k8s.io/ | 1.27.8 | 1 |
| alpine/ | 6dbe6f391eda | k8s.io/ | 1.25.16 | 1 |
| alpine/ | 7a319b15cfc9 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | 7e1e7d5b7a96 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | 9c4976d47656 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | bd01dae02676 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | cd560fce90f7 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | e5c0b053fed7 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | eec354133193 | k8s.io/ | 1.25.16 | 1 |
| alpine/ | fc059f056ad0 | k8s.io/ | 1.28.4 | 1 |
| amazon/ | b55277652ea8 | k8s.io/ | 1.25.16 | 1 |
| ambassador/ | 7a1ea0d934fb | k8s.io/ | 1.28.4 | 1 |
| apecloud/ | c93655ccb2d7 | k8s.io/ | 1.25.16 | 1 |
| bitnamilegacy/ | 1249fc292e84 | k8s.io/ | 1.25.16 | 1 |
| bitnamilegacy/ | 64614ef8290f | k8s.io/ | 1.25.16 | 1 |
| bitnamilegacy/ | 744f84cf7493 | k8s.io/ | 1.25.16 | 1 |
| burganbank/ | 9259c34e4037 | k8s.io/ | 1.25.16 | 1 |
| cgtysylr/ | aec0f8a38a77 | k8s.io/ | 1.28.4 | 1 |
| chriswells0/ | f3918ec8471c | k8s.io/ | 1.27.8 | 1 |
| crowdfox/ | 6fa7e8063d27 | k8s.io/ | 1.25.16 | 1 |
| csiplugin/ | 1fa83d45417f | k8s.io/ | 1.25.16 | 1 |