CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| milesmcc/ | e821e31140f7 | cryptography | 42.0.2 | 1 |
| milvusdb/ | fededb2f2d63 | openssl | no fix listed | 1 |
| milvusdb/ | a3a55e1c1497 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| mintproject/ | 222e3b941a36 | openssl | 3.1.4-r5 | 1 |
| mintproject/ | 83aade2c1855 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| miqm/ | c5c211717d9b | openssl | 3.0.13-1~deb12u1 | 1 |
| mirrorgitlabcontainers/ | 9efd73993c34 | cryptography | 42.0.2 | 1 |
| mlikiowa/ | 1336a777f9a4 | openssl | no fix listed | 1 |
| moreillon/ | d2ee0423b797 | openssl | 3.0.13-1~deb12u1 | 1 |
| mozilla/ | 016162bf39d8 | cryptography | 42.0.2 | 1 |
| mozilla/ | 93752877dced | cryptography | 42.0.2 | 1 |
| mpopoola1/ | 061fc532de7d | openssl | 3.0.12-r4 | 1 |
| mshanley80/ | 5b189a70c0fb | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| muhammedgamal/ | 74b4cd69b6fa | openssl | 3.0.13-1~deb12u1 | 1 |
| muluder/ | 43b597a93da7 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| muonsoft/ | c9afe1295484 | openssl | 3.0.12-r4 | 1 |
| mvance/ | 4bf67b567f39 | openssl | 3.0.13-1~deb12u1 | 1 |
| mvitale1989/ | 1504ccda06df | cryptography | 42.0.2 | 1 |
| mysql/ | e4ea36622cdd | cryptography | 42.0.2 | 1 |
| natsio/ | 59cf2e949181 | openssl | 3.0.12-r4 | 1 |
| natsio/ | c507bd7e3831 | openssl | 3.0.12-r4 | 1 |
| natsio/ | e808e0644ce1 | openssl | 3.1.4-r5 | 1 |
| natsio/ | bb241956b0dc | openssl | 3.1.4-r5 | 1 |
| natsio/ | 0d50270fa374 | openssl | 3.1.4-r5 | 1 |
| natsio/ | 8c28b75bc416 | openssl | 3.1.4-r5 | 1 |
| natsio/ | c3a755eab2cc | openssl | 3.1.4-r5 | 1 |
| natsio/ | 2adf791d9f9f | openssl | 3.1.4-r5 | 1 |
| ncsapolyglot/ | 438d82cdbdb5 | cryptography | 42.0.2 | 1 |
| neilpeterson/ | 8b645ac1a23e | cryptography | 42.0.2 | 1 |
| neilpeterson/ | 29d229ab446e | cryptography | 42.0.2 | 1 |
| neilpeterson/ | 39ce9f92e899 | cryptography | 42.0.2 | 1 |
| nelssec/ | 5e471f0cdeaa | openssl | no fix listed | 1 |
| neosu/ | 256530d8e5c6 | openssl | 3.1.4-r5 | 1 |
| netbirdio/ | 15a3aab9a345 | cryptography | 42.0.2 | 1 |
| netbirdio/ | 1b59e1c905c9 | cryptography | 42.0.2 | 1 |
| netbirdio/ | 332cc31f5f35 | cryptography | 42.0.2 | 1 |
| netbirdio/ | 88b5fb704a8c | cryptography | 42.0.2 | 1 |
| netboxcommunity/ | 3d652dca5351 | cryptography openssl | 42.0.2 3.0.2-0ubuntu1.14 | 1 |
| nethermind/ | 15517708c3b6 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| netskopeprivateaccess/ | 93e2fd164a93 | openssl | no fix listed | 1 |
| networkboot/ | e99bbfbd6fb2 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| ngick8stesting/ | 8dd6dea45be4 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| ngoduykhanh/ | 099371dd9ba6 | cryptography | 42.0.2 | 1 |
| ngoduykhanh/ | 9898a7cf37d2 | cryptography | 42.0.2 | 1 |
| nirmalnaveen/ | 8541a39162f3 | openssl | 3.0.13-1~deb12u1 | 1 |
| nlmacamp/ | 5dbb8589f824 | cryptography | 42.0.2 | 1 |
| nodered/ | e2632a7a35dd | openssl | 3.1.4-r5 | 1 |
| nottiey/ | 9c35a24c9eb3 | openssl | 3.0.12-r4 | 1 |
| nsqio/ | 1a369c146af7 | openssl | 3.1.4-r5 | 1 |
| okaforuchena/ | 004e81250f48 | openssl | 3.0.12-r4 | 1 |