CVE-2023-5678
MediumAdvisory
Published 6 Nov 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.045
- 91st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,585
- of 17,787 indexed, latest versions
- Container images
- 1,651
- deployed by those charts
- Fix available
- 4 of 5
- affected packages
libopenssl-1_1-devel-1.1.1w-4.1 on GA media
Carried by container images the latest versions of 1,585 of 17,787 indexed charts deploy, on 1,651 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+71 more | 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21, 1.1.1f-1ubuntu2.fips.21+3 more | 886 |
| opensslapk | 1.1.1l-r7, 1.1.1l-r8, 1.1.1m-r1, 1.1.1n-r0+27 more | 1.1.1w-r1, 3.0.12-r1, 3.1.4-r1 | 755 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-14.6.1, 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.0i-150100.14.68.1, 1.1.1d-150200.11.82.1, 1.1.1w-4.1 | 10 |
- OSV records
- ALPINE-CVE-2023-5678DEBIAN-CVE-2023-5678UBUNTU-CVE-2023-5678openSUSE-SU-2024:13437-1SUSE-SU-2023:4519-1SUSE-SU-2023:4520-1
- Also known as
- USN-6622-1, USN-6632-1, USN-6709-1
Charts affected
1,585 by stars
Container images carrying it
1,651 by charts deploying them
A fixed version is listed for 4 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| clickhouse/ | 512bb8a21483 | openssl | 1.1.1f-1ubuntu2.fips.21 | 1 |
| clickhouse/ | 810861a2e2d0 | openssl | no fix listed | 1 |
| clickhouse/ | 8745843b17f9 | openssl | no fix listed | 1 |
| clickhouse/ | 92098d3b31dd | openssl | no fix listed | 1 |
| clickhouse/ | a65ca89ddbe8 | openssl | no fix listed | 1 |
| clickhouse/ | b627d7a9bc0e | openssl | no fix listed | 1 |
| clickhouse/ | dc5658853ce1 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| clickhouse/ | e019438e1e05 | openssl | no fix listed | 1 |
| cloudnativelabs/ | 0ec7cd73f43f | openssl | 3.0.12-r1 | 1 |
| cloudve/ | af56e77ca587 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| cloudve/ | d79c1c5881c0 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| cnieg/ | d4b478d76f2a | openssl | 1.1.1w-r1 | 1 |
| codecov/ | 0475cb1c3136 | openssl | 3.1.4-r1 | 1 |
| coldatom/ | eae9e82da080 | openssl | 3.0.12-r1 | 1 |
| coldatom/ | 7c2fbbb41bcf | openssl | 3.0.12-r1 | 1 |
| collabora/ | 05299b452f7f | openssl | 3.0.13-1~deb12u1 | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | openssl | no fix listed | 1 |
| cortezaproject/ | 8eb7a26605c9 | openssl | 1.1.1f-1ubuntu2.fips.21 | 1 |
| cortezaproject/ | cb9f200de5d2 | openssl | no fix listed | 1 |
| countly/ | e3c238248f99 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| cradlepoint/ | 8f5720b0cd03 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| crazymax/ | 841b10cdae76 | openssl | 3.1.4-r1 | 1 |
| crazymax/ | fb307f5b87bf | openssl | 3.0.12-r1 | 1 |
| cribl/ | 762747cb6796 | openssl openssl1.0 | 1.1.1-1ubuntu2.1~18.04.23+esm4 1.0.2n-1ubuntu5.13+esm1 | 1 |
| csepulvedab/ | 227a6f2b0ff8 | openssl | 1.1.1w-r1 | 1 |
| csiplugin/ | 1fa83d45417f | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| curlimages/ | 5af13420d29b | openssl | 3.0.12-r1 | 1 |
| curlimages/ | 9e886c104cae | openssl | 1.1.1w-r1 | 1 |
| curlimages/ | d1658d9c8ef9 | openssl | 1.1.1w-r1 | 1 |
| curlimages/ | e83fef2d5a03 | openssl | 1.1.1w-r1 | 1 |
| cyverse/ | aa69d105b292 | openssl | no fix listed | 1 |
| dachichang/ | 7ccac90a935e | openssl | 3.0.13-1~deb12u1 | 1 |
| danny1dockerhub/ | e434683fcc89 | openssl | 3.0.12-r1 | 1 |
| daskdev/ | 052630f5ca04 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| dasmeta/ | fa657960dfec | openssl openssl1.0 | 1.1.1-1ubuntu2.1~18.04.23+esm4 1.0.2n-1ubuntu5.13+esm1 | 1 |
| datafuselabs/ | ba877ee6cb4d | openssl | 3.0.13-1~deb12u1 | 1 |
| datafuselabs/ | a936843b85b4 | openssl | 3.0.13-1~deb12u1 | 1 |
| datalayers/ | 17b292079239 | openssl | no fix listed | 1 |
| datalust/ | 9c731bb207a6 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| datalust/ | 3de34aed5642 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| datamate/ | 2dd66b722464 | openssl | no fix listed | 1 |
| davidvmar/ | e9ce2608f799 | openssl | 1.1.1w-r1 | 1 |
| dblaci/ | eea697611af4 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| ddosify/ | a43c5155fa1c | openssl | 3.0.13-1~deb12u1 | 1 |
| ddosify/ | 3c11e3182652 | openssl | 3.0.13-1~deb12u1 | 1 |
| ddosify/ | ac323d52bfb4 | openssl | 3.0.13-1~deb12u1 | 1 |
| ddosify/ | 181965edb12e | openssl | 1.1.1w-r1 | 1 |
| ddosify/ | a97a1b8a66af | openssl | 1.1.1w-r1 | 1 |
| ddosify/ | b796b8c73011 | openssl | 3.0.13-1~deb12u1 | 1 |
| deepflowce/ | bc1882f75c18 | openssl | 1.1.1f-1ubuntu2.21 | 1 |