CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pgpool/ | 3782cbf9bb0c | openssl | 3.0.12-r4 | 1 |
| phntom/ | 53883b65d9b7 | openssl | 3.1.4-r5 | 1 |
| phntom/ | 51cf9da4aa2e | openssl | 3.0.2-0ubuntu1.14 | 1 |
| phntom/ | 49b6488f618b | openssl | 3.0.12-r4 | 1 |
| photoprism/ | 2954334adbda | openssl | 3.0.2-0ubuntu1.14 | 1 |
| phsmith/ | 0265a7616ae8 | openssl | 3.1.4-r5 | 1 |
| pinclr/ | f37f250b7091 | openssl | 3.1.4-r5 | 1 |
| platform9community/ | de3fa9b70df1 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| platform9community/ | 40a4970de568 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| platform9community/ | 2089811e5cc6 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| platform9community/ | d1165c94dfb3 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| platform9community/ | 8d11b50368c6 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| plexinc/ | 46ea59b96f2b | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| plexinc/ | b598abb134ad | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| pnnlmiscscripts/ | 155131891741 | cryptography | 42.0.2 | 1 |
| pnnlmiscscripts/ | 79ada675515f | openssl | 3.0.12-r4 | 1 |
| pnnlmiscscripts/ | b85e437ae261 | openssl | 3.0.12-r4 | 1 |
| pnnlmiscscripts/ | fa8f5906d36a | openssl | 3.0.12-r4 | 1 |
| pnnlmiscscripts/ | 8af4b7551d40 | cryptography | 42.0.2 | 1 |
| portainer/ | 3e61aaee1341 | openssl | 3.1.4-r5 | 1 |
| postgis/ | 4738bee21eb6 | openssl | 3.1.4-r5 | 1 |
| pozetroninc/ | 53ae64f29da8 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| praravind1801/ | f29d637b9ce1 | openssl | 3.0.13-1~deb12u1 | 1 |
| prodrigestivill/ | 6ed2afadc326 | openssl | 3.0.12-r4 | 1 |
| project2team4/ | 3ff031a08887 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| prompve/ | ff6749eb03b0 | cryptography | 42.0.2 | 1 |
| pryorda/ | 79925e63e59f | cryptography | 42.0.2 | 1 |
| pryorda/ | e0f5ba8b7856 | cryptography | 42.0.2 | 1 |
| pschichtel/ | b543e9c2d371 | openssl | no fix listed | 1 |
| pschiffe/ | 37ebba8c2b8f | cryptography | 42.0.2 | 1 |
| psorab/ | 53b68896c4ce | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| ptthanh1511/ | 5741cbde85ab | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| pumejlab/ | f563eabcb819 | openssl | 3.0.12-r4 | 1 |
| puppet/ | 0b6fd9a6b7da | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| pyaephyohein/ | fdee05f2d441 | cryptography openssl | 42.0.2 3.1.4-r5 | 1 |
| pysga1996/ | fdeec30ad482 | openssl | 3.0.12-r4 | 1 |
| qbittorrentofficial/ | 2b86d9c356ae | openssl | 3.1.4-r5 | 1 |
| qdrant/ | 5f2a56b95266 | openssl | 3.0.13-1~deb12u1 | 1 |
| qdrant/ | 66ee661d5241 | openssl | 3.0.13-1~deb12u1 | 1 |
| qichenxu4pd/ | d758d41d9c6b | cryptography | 42.0.2 | 1 |
| qonstrukt/ | 089af7925aa1 | cryptography | 42.0.2 | 1 |
| quickwit/ | d29332bdadcc | openssl | 3.0.13-1~deb12u1 | 1 |
| qumine/ | c0b650d51132 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| rabeh/ | 941007b6946e | openssl | 3.0.2-0ubuntu1.14 | 1 |
| radondb/ | 4732df471073 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| rancher/ | e66f32d19eb9 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| razorbladex401/ | 6a4d79248e7d | openssl | no fix listed | 1 |
| rclone/ | 08e1af3c8814 | openssl | 3.1.4-r5 | 1 |
| redash/ | 9392753c0376 | cryptography | 42.0.2 | 1 |
| redislabs/ | b03ab1426d0d | cryptography | 42.0.2 | 1 |