CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| istio/ | 2232f365aed6 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| istio/ | 268ab879ea51 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| istio/ | 655eefa11c84 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| istio/ | 6cfce8a071b9 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| istio/ | 70f9d1fe5fff | openssl | 3.0.2-0ubuntu1.14 | 1 |
| istio/ | 294ca55bd1cc | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| istio/ | ac0284d75ec9 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| istio/ | c09319753454 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| istio/ | ce9d87606701 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| istio/ | db08d6963975 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| istio/ | e7e110a421c2 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| istio/ | 0c78be035e98 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| istio/ | 87a9db561d2e | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| istio/ | 88c6c693e67a | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| istio/ | df69c1a7af7c | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| jacobalberty/ | 4a3616625dda | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| jacobalberty/ | b3edc809a3ff | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| jacobalberty/ | c409924e2463 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| jakowenko/ | b858bac9e32a | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| jedi132000/ | dc2a81e92f23 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| jenkins/ | de4fea113221 | openssl | 3.0.13-1~deb12u1 | 1 |
| jertel/ | 4dcc0ef93efc | cryptography | 42.0.2 | 1 |
| jhipster/ | 7184525acd4d | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| jhoncytech/ | 18c3ca1f411e | openssl | 3.0.13-1~deb12u1 | 1 |
| jingking/ | 43e74ab234e1 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| jlesage/ | 0752dcb72bd1 | openssl | 3.0.12-r4 | 1 |
| jmferrer/ | 030f68ec6998 | cryptography openssl | 42.0.2 1.0.2g-1ubuntu4.20+esm11 | 1 |
| josepht05/ | 36cb0c618c94 | openssl | 3.0.12-r4 | 1 |
| josepht05/ | d94024965d78 | openssl | 3.0.12-r4 | 1 |
| josh5/ | 4d49c4816260 | nodejs openssl | no fix listed 3.0.2-0ubuntu1.14 | 1 |
| juicedata/ | 3e4daf9626d5 | openssl | 3.1.4-r5 | 1 |
| juicedata/ | 95008ba63318 | cryptography | 42.0.2 | 1 |
| juicedata/ | d915e899e322 | cryptography | 42.0.2 | 1 |
| jupyterhub/ | 7adeeed34a36 | openssl | 3.1.4-r5 | 1 |
| jupyterhub/ | 5a0ceed1300a | cryptography | 42.0.2 | 1 |
| jupyterhub/ | b6b4a1a34bf0 | cryptography openssl | 42.0.2 1.1.1f-1ubuntu2.21 | 1 |
| jupyterhub/ | e4770285aaf7 | cryptography openssl | 42.0.2 1.1.1f-1ubuntu2.21 | 1 |
| jupyterhub/ | 91f8f833fc1d | openssl | 3.1.4-r5 | 1 |
| jupyterhub/ | 8e4778efec8e | cryptography | 42.0.2 | 1 |
| jupyterhub/ | e3e6f3051df8 | cryptography openssl | 42.0.2 1.1.1f-1ubuntu2.21 | 1 |
| kafkakraft/ | 062d697db7e5 | openssl | no fix listed | 1 |
| kafkakraft/ | f261ad288fce | openssl | no fix listed | 1 |
| kafkakraft/ | 2e4b593b878b | openssl | no fix listed | 1 |
| keitaro/ | 5bf1a45f45c1 | cryptography | 42.0.2 | 1 |
| kennethreitz/ | 599fe5e50731 | cryptography openssl | 42.0.2 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| kfirfer/ | c257c1e0e8b9 | cryptography openssl | 42.0.2 3.1.4-r5 | 1 |
| kfirfer/ | c05d9fc7ae77 | openssl | 3.0.12-r4 | 1 |
| kfirfer/ | d23d173f333f | openssl | 3.1.4-r5 | 1 |
| kfirfer/ | 2efb4a5d74a3 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| kfirfer/ | 461331bd838e | openssl | 3.1.4-r5 | 1 |