CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,540
- of 17,787 indexed, latest versions
- Container images
- 1,551
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,540 of 17,787 indexed charts deploy, on 1,551 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 893 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 430 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 315 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,540 by stars
Container images carrying it
1,551 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| moreillon/ | b067dbbbb6af | openssl | 3.0.13-1~deb12u1 | 2 |
| natsio/ | e414cc7e6f59 | openssl | 3.0.12-r4 | 2 |
| natsio/ | 31c02aac089a | openssl | 3.0.12-r4 | 2 |
| ngick8stesting/ | 1e764eab77b4 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 2 |
| ngoduykhanh/ | ba36ab196d3d | cryptography | 42.0.2 | 2 |
| obsidiandynamics/ | 5337c9e0e2de | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| omecproject/ | cfdb566dd949 | cryptography openssl | 42.0.2 1.0.2g-1ubuntu4.20+esm11 | 2 |
| openebs/ | f6c18b0f8c8a | openssl | 3.0.2-0ubuntu1.14 | 2 |
| openebs/ | 6afe2123c457 | openssl | 3.0.2-0ubuntu1.14 | 2 |
| organizr/ | 1ce319d73cdf | openssl | 3.1.4-r5 | 2 |
| oryd/ | d06fc5845f63 | openssl | 3.1.4-r5 | 2 |
| oryd/ | e8cb9b79a89c | openssl | 3.1.4-r5 | 2 |
| outlinewiki/ | d060dcd8f9aa | openssl | 3.0.12-r4 | 2 |
| piomin/ | 871f784dd6bc | openssl | 3.0.2-0ubuntu1.14 | 2 |
| qichenxu4pd/ | f3a8502bc21b | openssl | 3.0.13-1~deb12u1 | 2 |
| quickwit/ | 363ff56ce456 | openssl | 3.0.13-1~deb12u1 | 2 |
| redis/ | 1c5f43fddcdd | openssl | no fix listed | 2 |
| redis/ | 72035434f455 | openssl | no fix listed | 2 |
| redis/ | e44b2b49d059 | openssl | no fix listed | 2 |
| rookout/ | 4451a6f6b8ec | openssl | 3.0.12-r4 | 2 |
| rookout/ | 51c0fce64467 | openssl | 3.0.12-r4 | 2 |
| shahanafarooqui/ | e2195188a451 | openssl | 3.0.12-r4 | 2 |
| sigp/ | 44aa773dcf27 | openssl | no fix listed | 2 |
| sigp/ | 9a62bb870545 | openssl | no fix listed | 2 |
| smartedge/ | 4cd63c22ce36 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| speckle/ | 4bd113093583 | openssl | 3.0.13-1~deb12u1 | 2 |
| streamnative/ | 0e6d7aa3ef32 | openssl | 1.1.1f-1ubuntu2.fips.20 | 2 |
| svtechnmaa/ | b2987abe57d3 | openssl | 3.0.2-0ubuntu1.14 | 2 |
| taigaio/ | 92fc0822564f | openssl | 3.1.4-r5 | 2 |
| taigaio/ | 570c8792ce80 | openssl | 3.0.12-r4 | 2 |
| temporalio/ | c0a44c26397b | openssl | 3.1.4-r5 | 2 |
| temporalio/ | af9c9349708f | openssl | 3.1.4-r5 | 2 |
| tzahi12345/ | 2f943d584711 | nodejs openssl | no fix listed 3.0.2-0ubuntu1.14 | 2 |
| uffizzi/ | 0344805f267b | openssl | 3.0.13-1~deb12u1 | 2 |
| victoriametrics/ | a83e5db0897a | openssl | 3.1.4-r5 | 2 |
| weblate/ | 69c160d37a3c | cryptography | 42.0.2 | 2 |
| wolveix/ | e103700ae6ae | openssl | no fix listed | 2 |
| wurstmeister/ | 7a7fd44a7210 | openssl | 1.0.1f-1ubuntu2.27+esm10 | 2 |
| gcr.io/ | fbe12aa24de6 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 2 |
| ghcr.io/ | 536358d7b17e | openssl | no fix listed | 2 |
| ghcr.io/ | 789692ab9193 | openssl | 3.0.12-r4 | 2 |
| ghcr.io/ | b1ba7b054af2 | cryptography | 42.0.2 | 2 |
| ghcr.io/ | 5be52524664c | nodejs openssl | no fix listed 3.0.2-0ubuntu1.14 | 2 |
| ghcr.io/ | 56f8617363b4 | openssl | 3.0.12-r4 | 2 |
| ghcr.io/ | 5f545698e907 | openssl | 3.0.2-0ubuntu1.14 | 2 |
| ghcr.io/ | f34f98405c10 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| ghcr.io/ | 103fbcec2314 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| ghcr.io/ | 9b6105be7ad0 | openssl | 1.1.1f-1ubuntu2.21 | 2 |
| ghcr.io/ | 305b3327ebba | cryptography | 42.0.2 | 2 |
| ghcr.io/ | 4ee0764310e7 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 2 |