CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| stackstorm/ | 09989a26c8b7 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| stackstorm/ | 19fdfffdbba8 | cryptography openssl | 42.0.2 1.1.1f-1ubuntu2.21 | 1 |
| stashapp/ | 24dbd7607174 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| statcan/ | 3921305425b8 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| streamnative/ | 11bceacec8fb | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| streamnative/ | ebcf7f033b54 | cryptography | 42.0.2 | 1 |
| su541/ | 371ee33f83c1 | openssl | 3.1.4-r5 | 1 |
| subsquid/ | 0889a857f192 | openssl | 3.0.12-r4 | 1 |
| subsquid/ | fa549779e9b1 | openssl | 3.0.12-r4 | 1 |
| substratusai/ | 61695be635eb | openssl | 3.0.13-1~deb12u1 | 1 |
| sumuduliya/ | b7788a2984a3 | openssl | 3.1.4-r5 | 1 |
| supabase/ | 7174d551d720 | openssl | 3.0.12-r4 | 1 |
| supabase/ | aa1c92c0cf32 | cryptography | 42.0.2 | 1 |
| supermq/ | 944a0be3563e | openssl | 3.1.4-r5 | 1 |
| svtechnmaa/ | a934ffd63d25 | openssl | no fix listed | 1 |
| svtechnmaa/ | 1d71314424aa | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| svtechnmaa/ | 67be2aba9436 | cryptography | 42.0.2 | 1 |
| svtechnmaa/ | 6d91c2e4e882 | openssl | 3.1.4-r5 | 1 |
| svtechnmaa/ | 410a25b51f9f | openssl | 3.0.2-0ubuntu1.14 | 1 |
| svtechnmaa/ | 18394b08e6c3 | openssl | 3.0.13-1~deb12u1 | 1 |
| svtechnmaa/ | 6e368ace0977 | cryptography openssl | 42.0.2 1.1.1f-1ubuntu2.21 | 1 |
| svtechnmaa/ | 8e8abe71a46d | openssl | 3.1.4-r5 | 1 |
| svtechnmaa/ | 1a75d88031fe | openssl | 3.1.4-r5 | 1 |
| swaggerapi/ | 342808e22de4 | openssl | 3.1.4-r5 | 1 |
| sysintelligent/ | 77fb30df847d | openssl | 3.0.12-r4 | 1 |
| sysnet4admin/ | bc25b152d88e | openssl | no fix listed | 1 |
| tachyongroup/ | 7e79b9000856 | cryptography | 42.0.2 | 1 |
| tachyongroup/ | f4f7fabe1037 | cryptography | 42.0.2 | 1 |
| taigaio/ | 9f97323cc150 | cryptography | 42.0.2 | 1 |
| tautulli/ | c4da15f058ea | cryptography | 42.0.2 | 1 |
| tawfiq58/ | c707555f6853 | openssl | 3.0.12-r4 | 1 |
| teknas09/ | 12a1fa85c4aa | openssl | 3.0.13-1~deb12u1 | 1 |
| temporalio/ | 258958fe2ff2 | openssl | 3.1.4-r5 | 1 |
| temporalio/ | 836af062af30 | openssl | 3.1.4-r5 | 1 |
| temporalio/ | ddeebf8bad8f | openssl | 3.1.4-r5 | 1 |
| tensorflow/ | 8a208c232297 | openssl | no fix listed | 1 |
| tensorflow/ | 1e3172090703 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| theradius/ | 63ba348546ec | openssl | 3.0.13-1~deb12u1 | 1 |
| thesisrobot/ | 16b368e4d52c | openssl | 3.0.2-0ubuntu1.14 | 1 |
| thesisrobot/ | 287129953689 | openssl | 3.1.4-r5 | 1 |
| thirtythreeforty/ | f564c4f538de | openssl | 3.0.12-r4 | 1 |
| thmmniii/ | 5438517d9fc2 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| thmmniii/ | 86105349c1a3 | openssl | 3.1.4-r5 | 1 |
| thongngo3301/ | a341af5976e3 | openssl | 3.0.13-1~deb12u1 | 1 |
| timescale/ | 645fd9e92d76 | openssl | 3.1.4-r5 | 1 |
| timescale/ | a8e3322e1cf9 | cryptography openssl | 42.0.2 3.0.2-0ubuntu1.14 | 1 |
| timescale/ | cdb9ae118899 | cryptography openssl | 42.0.2 3.0.2-0ubuntu1.14 | 1 |
| timescale/ | d7db8f1085a3 | cryptography openssl | 42.0.2 no fix listed | 1 |
| timescale/ | e8d0a9cc3db5 | cryptography openssl | 42.0.2 no fix listed | 1 |
| timescale/ | ed719c0cd19d | cryptography openssl | 42.0.2 3.0.2-0ubuntu1.14 | 1 |