StackRadar

CVE-2023-5752

Medium

Advisory

Published 25 Oct 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
751
of 17,781 indexed, latest versions
Container images
781
deployed by those charts
Fix available
1 of 2
affected packages

Command Injection in pip when used with Mercurial

Carried by container images the latest versions of 751 of 17,781 indexed charts deploy, on 781 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+50 more23.3781
python-pipdeb23.0.1+dfsg-1no fix listed25
OSV records
GHSA-mq26-g339-26xfDEBIAN-CVE-2023-5752
Also known as
PYSEC-2023-228

Charts affected

751 by stars
ChartLatestAffected imagesRadar Score
trainingcollectorassist-iot-fl-training-collector1.1.01 of 1See more

trainingcollector assist-iot-fl-training-collector 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/fl_training_collector:latest792715dd3084
pip@23.2.1
23.3

Open the chart page →

1,719
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
pip@9.0.3
23.3

Open the chart page →

13,352
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
23.3

Open the chart page →

10,061
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
pip@22.0.2
23.3

Open the chart page →

18,277
resource-provisioningassist-iot-resource-provisioning1.0.04 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

4 of the 7 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
pip@23.0.1
23.3
assistiot/resource-provisioning_im:1.0.0a942dc14030a
pip@23.0.1
23.3
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
pip@20.3.4
23.3
library/mysql:5.74bc6bc963e6d
pip@23.0.1
23.3

Open the chart page →

8,032
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pip@23.0.1
23.3
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pip@23.0.1
23.3
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed
library/mysql:5.74bc6bc963e6d
pip@23.0.1
23.3

Open the chart page →

45,363
traffic-classificationassist-iot-traffic-classification2.0.01 of 2See more

traffic-classification assist-iot-traffic-classification 2.0.0

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/traffic-classification_api:2.0.0e32b87786142
pip@23.0.1
23.3

Open the chart page →

1,166
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
pip@23.0.1
23.3

Open the chart page →

13,913
phonebook-chartasumankamberoglu0.1.53 of 3See more

phonebook-chart asumankamberoglu 0.1.5

3 of the 3 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
23.3
paulkellerman/resultserver-app:1.0381eeccb0618
pip@22.3
23.3
paulkellerman/webserver-app:latest5a37b74f61b9
pip@22.3
23.3

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
pip@23.2.1
23.3

Open the chart page →

9,412
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
pip@21.2.4
23.3

Open the chart page →

5,507
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
pip@22.2.2
23.3

Open the chart page →

5,074
aws-ecr-credentialaws-ecr-credentialVerified publisher1.5.21 of 1See more

aws-ecr-credential aws-ecr-credential 1.5.2

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
pip@19.2.1
23.3

Open the chart page →

1,437
ecr-exporteraws-exportersVerified publisher0.2.41 of 1See more

ecr-exporter aws-exporters 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
pip@20.3.4
23.3

Open the chart page →

1,622
inspector-exporteraws-exportersVerified publisher0.0.21 of 1See more

inspector-exporter aws-exporters 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
pip@20.3.4
23.3

Open the chart page →

1,622
aws-secrets-synchronizeraws-secrets-synchronizer0.2.11 of 1See more

aws-secrets-synchronizer aws-secrets-synchronizer 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
ghcr.io/reezogit/aws-secrets-synchronizer:0.2.1111ed7cf7b39
pip@23.2.1
23.3

Open the chart page →

956
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pip@22.0.4
23.3

Open the chart page →

4,568
azure-app-exporterazure-app-exporterVerified publisher0.4.21 of 2See more

azure-app-exporter azure-app-exporter 0.4.2

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pip@21.2.4
23.3

Open the chart page →

1,790
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
pip@20.2.4
23.3

Open the chart page →

5,521
aks-helloworldazure-sample0.1.11 of 1See more

aks-helloworld azure-sample 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
23.3

Open the chart page →

4,269
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
23.3

Open the chart page →

5,224
azure-vote-osbaazure-sample0.1.01 of 1See more

azure-vote-osba azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
23.3

Open the chart page →

4,269
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
23.3

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
23.3

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
23.3

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
23.3

Open the chart page →

3,425
osba-text-analytics-demoazure-sample0.1.01 of 1See more

osba-text-analytics-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
23.3

Open the chart page →

3,089
twitter-sentimentazure-sample0.1.03 of 3See more

twitter-sentiment azure-sample 0.1.0

3 of the 3 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
23.3
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
23.3
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
23.3

Open the chart page →

11,833
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
conduction/balance-registration-varnish:dev07c44005da9d
pip@9.0.1
23.3

Open the chart page →

8,408
pvc-exporterbalihb-pvc-exporterVerified publisher0.2.42 of 2See more

pvc-exporter balihb-pvc-exporter 0.2.4

2 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
balihb/block-pvc-scanner:0.2.45b95e1cf1158
pip@21.2.4
23.3
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
pip@21.2.4
23.3

Open the chart page →

2,765
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
pip@20.1.1
23.3

Open the chart page →

20,671
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
behnambm/docker-sample:v1bd3ad88afff9
pip@23.0.1
23.3

Open the chart page →

2,727
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
pip@20.0.2
23.3

Open the chart page →

7,956
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
pip@21.1.2
23.3

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed

Open the chart page →

10,145
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
pip@19.1.1
23.3

Open the chart page →

18,980
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-rwd:log74ded2d92f07
pip@23.0.1
23.3

Open the chart page →

26,996
puppetboardbootcVerified publisher0.1.41 of 1See more

puppetboard bootc 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
bootc/puppetboard:1.1.0f1383295e7be
pip@19.2.3
23.3

Open the chart page →

1,292
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
23.3

Open the chart page →

2,018
medusabryanalves0.1.01 of 1See more

medusa bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
23.3

Open the chart page →

147
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
23.3

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
pip@9.0.0
23.3

Open the chart page →

923
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pip@20.3.4
23.3

Open the chart page →

2,573
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pip@22.0.4
23.3

Open the chart page →

2,507
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
pip@21.2.1
23.3

Open the chart page →

4,518
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
23.3

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
pip@18.1
23.3

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
23.3

Open the chart page →

2,490
snow-webhookcamptocamp31.0.01 of 1See more

snow-webhook camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
23.3

Open the chart page →

1,310
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
pip@23.0.1
23.3

Open the chart page →

1,146

Container images carrying it

781 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
pip@8.1.1
23.3
2
pypiserver/pypiserver:v1.3.2303ac89b2aa2
pip@19.3.1
23.3
2
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
pip@20.3.3
23.3
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
pip@20.0.2
23.3
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
pip@20.0.2
23.3
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
pip@22.0.2
23.3
2
weblate/weblate:4.2.2-169c160d37a3c
pip@20.2.2
23.3
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
pip@19.0.3
23.3
2
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
pip@22.3
23.3
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pip@9.0.3
23.3
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
pip@9.0.3
23.3
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
pip@9.0.3
23.3
2
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
pip@22.1.2
23.3
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
pip@9.0.3
23.3
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
pip@9.0.3
23.3
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
pip@9.0.3
23.3
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
pip@9.0.1
23.3
1
acockburn/appdaemon:4.0.83a93281d7e94
pip@21.0.1
23.3
1
afrank/mozalert-controller:latestd463c37b08d7
pip@20.1.1
23.3
1
akeyless/base-rhel:0.0.14ba8900a0061
pip@20.2.4
23.3
1
alaaamin/reload-count-tornado-py-app:v1.0.1alpine46da5844794e
pip@22.0.4
23.3
1
alerta/alerta-web:8.5.04786b9eaa606
pip@20.1.1
23.3
1
alexeyr7/sf-test-app:latestdf0b41fdbd53
pip@22.0.4
23.3
1
alexvm6/generator:latestfb99ee4f760a
pip@22.3.1
23.3
1
alexvm6/pythonalex:latest89a05786879c
pip@22.3.1
23.3
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
pip@9.0.3
23.3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
pip@9.0.1
23.3
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pip@22.3.1
23.3
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pip@22.3.1
23.3
1
alpine/k8s:1.22.600ac10bcb759
pip@22.0.4
23.3
1
alpine/k8s:1.27.321b24e6bf801
pip@23.1.2
23.3
1
alpine/k8s:1.18.16a41efe02a041
pip@21.2.1
23.3
1
alpine/k8s:1.28.2fc059f056ad0
pip@23.2.1
23.3
1
amagdi888/my-repo:hello-appd8a10fc8faf6
pip@22.0.4
23.3
1
amancevice/superset:0.28.1c8c04bfe3d66
pip@19.0.3
23.3
1
amd64/mysql:5.7e20a653e0f51
pip@23.0.1
23.3
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
pip@20.0.2
23.3
1
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
pip@20.2.2
23.3
1
amundsendev/amundsen-search:2.4.099dda9502c3e
pip@20.2.2
23.3
1
anchore/anchore-engine:v0.10.0bde9eedf639d
pip@19.3.1
23.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
pip@9.0.3
23.3
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
pip@22.0.2
23.3
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pip@23.0.1
23.3
1
apache/bookkeeper:4.14.5a7d9970c148f
pip@9.0.3
23.3
1
apache/hadoop:3af361b20bec0
pip@8.1.2
23.3
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
pip@22.0.2
23.3
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
pip@20.0.2
23.3
1
apachepulsar/pulsar:2.6.14db6ff0b4045
pip@20.2.2
23.3
1
apachepulsar/pulsar:3.0.79c9947de139d
pip@22.0.2
23.3
1
apachepulsar/pulsar:2.9.0d056c89b7131
pip@21.3.1
23.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.