CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,532
- of 17,781 indexed, latest versions
- Container images
- 1,541
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,532 of 17,781 indexed charts deploy, on 1,541 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 892 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 426 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 310 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,532 by stars
Container images carrying it
1,541 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| selenium/ | 02f251d48d5f | openssl | 1.1.1f-1ubuntu2.21 | 3 |
| sigp/ | 50f66cfebb6d | openssl | no fix listed | 3 |
| xenondb/ | 0e26872a2b67 | openssl | 1.1.1f-1ubuntu2.21 | 3 |
| ghcr.io/ | 6a5594b7b32c | openssl | 3.0.13-1~deb12u1 | 3 |
| quay.io/ | 2b6db27eaf3d | openssl | 3.0.2-0ubuntu1.14 | 3 |
| quay.io/ | 39f2c6e0af38 | openssl | 1.1.1f-1ubuntu2.21 | 3 |
| quay.io/ | 4c3b91bebd3d | openssl | 1.0.2g-1ubuntu4.20+esm11 | 3 |
| quay.io/ | 4286bcccda3e | openssl | 3.1.4-r5 | 3 |
| quay.io/ | f296c2ec5db7 | openssl | 3.0.2-0ubuntu1.14 | 3 |
| quay.io/ | eec0305b594c | openssl | 3.1.4-r5 | 3 |
| quay.io/ | fd916f75415f | openssl | 3.1.4-r5 | 3 |
| quay.io/ | 1b33357b3595 | openssl | 3.1.4-r5 | 3 |
| registry.k8s.io/ | e5c4824e7375 | openssl | 3.1.4-r5 | 3 |
| agoldis/ | afaa5a84051d | openssl | 3.1.4-r5 | 2 |
| agoldis/ | e061e5714238 | openssl | 3.0.12-r4 | 2 |
| agoldis/ | 10228ecd353b | openssl | 3.1.4-r5 | 2 |
| amancevice/ | 12a0a9e66550 | cryptography | 42.0.2 | 2 |
| apache/ | 7cdfd8deec92 | openssl | no fix listed | 2 |
| apache/ | ae0b86d3c4d0 | cryptography | 42.0.2 | 2 |
| cfssl/ | c9018c2ddf0b | openssl | 3.0.13-1~deb12u1 | 2 |
| chatwoot/ | d530ab8c1753 | openssl | 3.1.4-r5 | 2 |
| clickhouse/ | ed9640bfff07 | openssl | 1.1.1f-1ubuntu2.fips.20 | 2 |
| clickhouse/ | fa394da808cc | openssl | no fix listed | 2 |
| confluentinc/ | ac776fad95a5 | cryptography | 42.0.2 | 2 |
| confluentinc/ | cae577096489 | cryptography | 42.0.2 | 2 |
| cs3org/ | 02a9e78757b4 | cryptography openssl | 42.0.2 3.0.12-r4 | 2 |
| curlimages/ | 4a3396ae573c | openssl | 3.1.4-r5 | 2 |
| daniacobext/ | 9eae4d39fc33 | openssl | 3.0.12-r4 | 2 |
| datagrok/ | f5876d3aebb8 | openssl | no fix listed | 2 |
| eqalpha/ | 6537505c4235 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| eqalpha/ | eceb1806730c | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| freeradius/ | 21c8bfa904d8 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 2 |
| geoservercloud/ | 756559ee788a | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| geoservercloud/ | 99540eef78ad | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| geoservercloud/ | 5c254c53a357 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| geoservercloud/ | c687b1cbc891 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| geoservercloud/ | 5288f320cf36 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| geoservercloud/ | a30a60ac6cd0 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| gjeanmart/ | 926264c8f2d1 | openssl | 3.0.13-1~deb12u1 | 2 |
| gradiant/ | 015b30d5fa0f | openssl | no fix listed | 2 |
| grafana/ | d947e68a84d9 | openssl | 3.1.4-r5 | 2 |
| hashicorp/ | 6b4e5dadf082 | openssl | 3.1.4-r5 | 2 |
| hashicorp/ | 5d74a885ae3e | openssl | 3.1.4-r5 | 2 |
| hjacobs/ | 4b2147f47425 | cryptography openssl | 42.0.2 3.0.13-1~deb12u1 | 2 |
| hjacobs/ | 58221b57d4d2 | cryptography | 42.0.2 | 2 |
| hookiesolutions/ | 0629694246ba | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| hyperledger/ | a674d35eec9a | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| inaccel/ | 187fd448b6f2 | openssl | 3.0.12-r4 | 2 |
| interlayhq/ | a66d0e35e70f | openssl | 1.1.1f-1ubuntu2.fips.20 | 2 |
| interlayhq/ | c3e311de67da | openssl | 1.1.1f-1ubuntu2.21 | 2 |