CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| grafana/ | 0679e877ba20 | openssl | 3.1.4-r5 | 1 |
| grafana/ | 1a359d92f40e | openssl | 3.0.12-r4 | 1 |
| grafana/ | 1b9ca4bbc4a2 | openssl | 3.1.4-r5 | 1 |
| grafana/ | 39c849cebccc | openssl | 3.0.12-r4 | 1 |
| grafana/ | 6b5b37eb35bb | openssl | 3.1.4-r5 | 1 |
| grafana/ | 8640e5038e83 | openssl | 3.1.4-r5 | 1 |
| grafana/ | 6074e01dbe03 | openssl | 3.1.4-r5 | 1 |
| grafana/ | 757b5fadf816 | openssl | 3.1.4-r5 | 1 |
| grafana/ | 28d7c00588aa | openssl | 3.1.4-r5 | 1 |
| grafana/ | 39baf6d67f85 | openssl | 3.1.4-r5 | 1 |
| grafana/ | 4249db29b992 | openssl | 3.1.4-r5 | 1 |
| graylog/ | 19de1aff48c2 | openssl | no fix listed | 1 |
| guacamole/ | 0f62f6d17ab3 | openssl | no fix listed | 1 |
| guacamole/ | 38232cae2713 | openssl | 3.1.4-r5 | 1 |
| gulacedia/ | 67b467d961ca | openssl | 3.0.13-1~deb12u1 | 1 |
| hamid2021/ | 429d99890c3c | openssl | 3.0.12-r4 | 1 |
| hamidyousefi93/ | c34f071f6ed0 | openssl | 3.0.13-1~deb12u1 | 1 |
| hansehe/ | 58e09540afbc | openssl | 3.1.4-r5 | 1 |
| haproxytech/ | 8951be4b4e1c | openssl | 3.1.4-r5 | 1 |
| hashicorp/ | 712fe02d2f84 | openssl | 3.1.4-r5 | 1 |
| hashicorp/ | ddff34041c5c | openssl | 3.0.12-r4 | 1 |
| hashicorp/ | 0e4452f0f265 | openssl | 3.1.4-r5 | 1 |
| hashicorp/ | 62bed1bf8106 | openssl | 3.0.12-r4 | 1 |
| hashicorp/ | 4dcb45513699 | openssl | 3.1.4-r5 | 1 |
| hashicorp/ | 0b01ed3924e6 | openssl | 3.1.4-r5 | 1 |
| hashicorp/ | 4500e988b7ce | openssl | 3.0.12-r4 | 1 |
| hashicorp/ | 97d521a27498 | openssl | 3.0.12-r4 | 1 |
| hasura/ | 0111b0204136 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| hasura/ | f6c1c4b957d2 | openssl | no fix listed | 1 |
| haugene/ | 059216cfae4b | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| haveagitgat/ | 1256348872ce | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| haveagitgat/ | 1e3f9328327d | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| haveagitgat/ | 3ff0913202dd | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| hazelcast/ | 8fe26efde8e1 | openssl | 3.1.4-r5 | 1 |
| headwindmdm/ | 3550b4840840 | openssl | no fix listed | 1 |
| healthchecks/ | e82bb0836e30 | cryptography | 42.0.2 | 1 |
| helga09/ | a03657d97897 | cryptography | 42.0.2 | 1 |
| helicone/ | 4c69b971a7e4 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| helicone/ | 4a913936c97b | openssl | 3.0.13-1~deb12u1 | 1 |
| hetznercloud/ | 8c07e6d7a76c | openssl | 3.1.4-r5 | 1 |
| hhyo/ | 1aa41843419e | cryptography | 42.0.2 | 1 |
| hiboxsystems/ | dcffb926e563 | openssl | 3.0.13-1~deb12u1 | 1 |
| hivemq/ | 241d6a8e1963 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| hiversh/ | 839226cc6e41 | openssl | no fix listed | 1 |
| hjacobs/ | 5d328c003efe | cryptography | 42.0.2 | 1 |
| hjacobs/ | fbb303ed463c | cryptography openssl | 42.0.2 3.0.13-1~deb12u1 | 1 |
| hjacobs/ | a4fae38f93d7 | cryptography | 42.0.2 | 1 |
| hjacobs/ | 45f93491c434 | cryptography | 42.0.2 | 1 |
| hjacobs/ | c173cd02f5af | cryptography | 42.0.2 | 1 |
| hjacobs/ | 431f1bf013d0 | cryptography openssl | 42.0.2 3.0.13-1~deb12u1 | 1 |