CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| dpage/ | a5a656e1d5fd | cryptography | 42.0.2 | 1 |
| dpage/ | b1f00b8163cf | cryptography | 42.0.2 | 1 |
| dragonflyoss/ | edf3e921f4e0 | openssl | 3.0.13-1~deb12u1 | 1 |
| dremio/ | 80ed2e3b7c43 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| drgrove/ | 361721759a2b | cryptography | 42.0.2 | 1 |
| drpcorg/ | 8858fae1859d | openssl | 3.0.2-0ubuntu1.14 | 1 |
| dserio83/ | b4e1ec6664d3 | openssl | 3.1.4-r5 | 1 |
| dtzar/ | a1041bb0f1d1 | openssl | 3.0.12-r4 | 1 |
| duck1123/ | 0e29f19fa67c | openssl | 3.0.2-0ubuntu1.14 | 1 |
| duck1123/ | 9d6fb247b714 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| dysnix/ | 19951e3e7a32 | cryptography | 42.0.2 | 1 |
| elastic/ | c7a1c63257d0 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| elastichq/ | bb3bd22c2b87 | cryptography | 42.0.2 | 1 |
| elastictranscoder/ | 963ab3858c6b | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| elastictranscoder/ | 26208b8c2359 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| elastictranscoder/ | b4a0327029e6 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| elastictranscoder/ | 5b75d19e2733 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| empathyco/ | 03e724e41eeb | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| enclavenetworks/ | 0a99759300d1 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| engrmth/ | 6d8464e6f0e8 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| envoyproxy/ | 2956bd9de830 | openssl | no fix listed | 1 |
| envoyproxy/ | 447f857a0146 | openssl | no fix listed | 1 |
| envoyproxy/ | 56da5afd7df3 | openssl | no fix listed | 1 |
| envoyproxy/ | caa5b411be16 | openssl | no fix listed | 1 |
| envoyproxy/ | cfc0678bc03c | openssl | no fix listed | 1 |
| envoyproxy/ | e596fda6a0ce | openssl | no fix listed | 1 |
| envoyproxy/ | e8b37c1d7578 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| envsubst/ | 90963c70db69 | openssl | 3.1.4-r5 | 1 |
| epamedp/ | 28ef56bc0ca3 | openssl | 3.1.4-r5 | 1 |
| eqalpha/ | f1d60f12cb3c | openssl | 3.1.4-r5 | 1 |
| eqalpha/ | fd9351ce27a7 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| errbotio/ | 00ee4e0953ab | cryptography | 42.0.2 | 1 |
| esphome/ | 3f51ec10e823 | cryptography | 42.0.2 | 1 |
| esphome/ | 9ab8cc88b28c | openssl | 3.0.13-1~deb12u1 | 1 |
| ethanbergstrom/ | 345c2a46c103 | cryptography | 42.0.2 | 1 |
| ethereumex/ | a7603aa8df4c | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| ethersphere/ | 56029b0985f4 | openssl | 3.1.4-r5 | 1 |
| ethpandaops/ | ad26158420dd | openssl | 3.1.4-r5 | 1 |
| ethpandaops/ | c58eb9ffe446 | openssl | 3.0.12-r4 | 1 |
| evgkrsk/ | 37f0e1f435c3 | openssl | 3.0.12-r4 | 1 |
| evk02/ | ef6ff257ef35 | cryptography | 42.0.2 | 1 |
| factly/ | ca5bc71d1d5c | cryptography | 42.0.2 | 1 |
| factly/ | 9db4bee30e63 | openssl | 3.0.12-r4 | 1 |
| factly/ | 742355964b0e | openssl | 3.1.4-r5 | 1 |
| fedodo/ | 28dada8e3216 | openssl | 3.0.12-r4 | 1 |
| fedodo/ | 8f8eb7a1207e | openssl | 3.0.12-r4 | 1 |
| fedodo/ | c69413c4d690 | openssl | 3.0.12-r4 | 1 |
| fedodo/ | b2b540081c21 | openssl | 3.0.12-r4 | 1 |
| felipecs8/ | 4e51693fcdf5 | openssl | 3.0.12-r4 | 1 |
| felipecs8/ | d5f4f17cb066 | openssl | 3.0.12-r4 | 1 |