StackRadar

CVE-2023-5752

Medium

Advisory

Published 25 Oct 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
755
of 17,790 indexed, latest versions
Container images
785
deployed by those charts
Fix available
1 of 2
affected packages

Command Injection in pip when used with Mercurial

Carried by container images the latest versions of 755 of 17,790 indexed charts deploy, on 785 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+50 more23.3785
python-pipdeb23.0.1+dfsg-1no fix listed25
OSV records
GHSA-mq26-g339-26xfDEBIAN-CVE-2023-5752
Also known as
PYSEC-2023-228

Charts affected

755 by stars
ChartLatestAffected imagesRadar Score
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
pip@22.3.1
23.3

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
pip@9.0.3
23.3

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
pip@22.3.1
23.3

Open the chart page →

1,838
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
pip@21.2.4
23.3

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
pip@21.2.4
23.3

Open the chart page →

1,636

Container images carrying it

785 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
pip@21.0
23.3
1
voltha/voltha-cli:1.6.0c4e41e92f046
pip@8.1.1
23.3
1
voltha/voltha-netconf:1.6.037f80524c207
pip@8.1.1
23.3
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
pip@8.1.1
23.3
1
voltha/voltha-tester:1.7.0655c3048a602
pip@8.1.1
23.3
1
voltha/voltha-voltha:1.6.0ff596b62de59
pip@8.1.1
23.3
1
wallarm/sysbindings:v0.9.9c527865df85d
pip@22.2.1
23.3
1
wazuh/wazuh-manager:4.4.121994f40e0da
pip@23.0.1
23.3
1
weblate/weblate:3.11.3-182848df56ecd
pip@18.1
23.3
1
wiktorn/overpass-api:latest9bb5f4a9b54c
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed
1
wiremind/pghoard:12-2019-11-264dea42c8166c
pip@19.3.1
23.3
1
witcherek7/pav:0.0.342a744f29ac0
pip@22.3.1
23.3
1
xeladock/mysql_dns:latest4baf531453f1
pip@22.0.2
23.3
1
ygqygq2/mysql-exec-sql:latest54f30def1558
pip@20.2.4
23.3
1
youssef11gaber10/deployment-weather-flask:latest96bce8b8b5a7
pip@23.0.1
23.3
1
yugabytedb/yugabyte:2026.1.1.1-b23926eedf0ff4
pip@9.0.3
23.3
1
yugabytedb/yugabyte:2026.1.1.0-b91de2e00278645
pip@9.0.3
23.3
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pip@21.2.4
23.3
1
zohardocker12/weather_app_flask:latestb86d60dbb68d
pip@21.1.3
23.3
1
gcr.io/google-samples/microservices-demo/loadgenerator:v0.2.3360130ab5850
pip@21.0.1
23.3
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
pip@21.0.1
23.3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
pip@23.0.1
23.3
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
pip@22.0.4
23.3
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
pip@23.0.1
23.3
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
pip@9.0.3
23.3
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
pip@20.3.4
23.3
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
pip@20.3.4
23.3
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
pip@23.0.1
23.3
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
pip@20.3.4
23.3
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pip@20.3.4
23.3
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pip@20.3.4
23.3
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed
1
ghcr.io/cloudnative-pg/postgresql:18899d3ed526b6
pip@20.3.4
23.3
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
pip@20.3.4
23.3
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pip@23.0.1
23.3
1
ghcr.io/cunningpike/fediblockhole:0.4.22abc5f0350dc
pip@22.3.1
23.3
1
ghcr.io/dask/dask:2024.1.0080150de7d86
pip@23.2.1
23.3
1
ghcr.io/dask/dask-gateway-server:2024.1.0881e7acfc5a0
pip@23.2.1
23.3
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
pip@23.0.1
23.3
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
pip@21.2.4
23.3
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pip@22.0.4
23.3
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pip@21.2.4
23.3
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
pip@23.2.1
23.3
1
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
pip@9.0.3
23.3
1
ghcr.io/eshepelyuk/dckr/cmak2zk:1.2.022de6314c31e
pip@21.2.4
23.3
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
pip@20.2.4
23.3
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pip@22.0.3
23.3
1
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
pip@23.1.2
23.3
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
pip@20.0.2
23.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.