CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,532
- of 17,787 indexed, latest versions
- Container images
- 1,541
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,532 of 17,787 indexed charts deploy, on 1,541 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 892 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 426 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 310 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,532 by stars
Container images carrying it
1,541 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apache/ | afa47bf1692a | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| apache/ | 63b8e3e40742 | openssl | no fix listed | 1 |
| apachepulsar/ | 16f9fdab3fa6 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| apachepulsar/ | 3b262ab7a7d9 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| apachepulsar/ | 9c9947de139d | openssl | no fix listed | 1 |
| apachepulsar/ | d056c89b7131 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| apachepulsar/ | d538416d5afe | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| apache/ | 76c176e8a0e4 | openssl | no fix listed | 1 |
| apache/ | c8fb51195444 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| apache/ | 133d35d2c263 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| apache/ | b4ec8c18d079 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| apache/ | 295f1dc87d98 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| apache/ | 80530f0308a5 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| apache/ | 975ab033580d | cryptography | 42.0.2 | 1 |
| apache/ | ab9467fd712c | openssl | 3.0.13-1~deb12u1 | 1 |
| apache/ | 92d055a84e9e | openssl | 3.0.2-0ubuntu1.14 | 1 |
| apecloud/ | 8ac9947a2c84 | cryptography | 42.0.2 | 1 |
| apecloud/ | c93655ccb2d7 | openssl | 3.1.4-r5 | 1 |
| aquasec/ | 6672264accce | openssl | 3.1.4-r5 | 1 |
| aquasec/ | 0795cba777e7 | openssl | 3.1.4-r5 | 1 |
| aquasec/ | c0467c3941dc | openssl | 3.1.4-r5 | 1 |
| aquasec/ | 944a04445179 | openssl | 3.1.4-r5 | 1 |
| arconixforge/ | c08d7c438966 | cryptography | 42.0.2 | 1 |
| arilot/ | 27a4f7e0f9f1 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| artur9010/ | 6b4de3ce8b0e | openssl | 3.0.13-1~deb12u1 | 1 |
| assistiot/ | c3adbab6a3e7 | cryptography | 42.0.2 | 1 |
| assistiot/ | 16d21bc5e42e | openssl | 3.1.4-r5 | 1 |
| assistiot/ | 27d58b8911cd | openssl | 3.1.4-r5 | 1 |
| assistiot/ | 0aacefac9677 | cryptography | 42.0.2 | 1 |
| assistiot/ | 6a107f224c34 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| assistiot/ | d157fbe150e3 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| assistiot/ | 0d3e6d35f168 | openssl | 3.0.13-1~deb12u1 | 1 |
| assistiot/ | e9bae124095f | openssl | 3.0.2-0ubuntu1.14 | 1 |
| assistiot/ | 68324d0fa5bb | openssl | 3.0.12-r4 | 1 |
| assistiot/ | 30812ba93555 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| assistiot/ | 44a37b00d4f8 | openssl | 3.1.4-r5 | 1 |
| assistiot/ | a942dc14030a | openssl | 3.1.4-r5 | 1 |
| assistiot/ | ea254b6d8a31 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| assistiot/ | 2a2587804717 | openssl | 3.1.4-r5 | 1 |
| assistiot/ | 4f41e1defe99 | openssl | 3.0.12-r4 | 1 |
| assistiot/ | 89f37e88c871 | openssl | 3.0.12-r4 | 1 |
| assistiot/ | 7d6a0d534c7f | openssl | 3.0.13-1~deb12u1 | 1 |
| assistiot/ | a8b8dbed04a4 | openssl | 3.0.12-r4 | 1 |
| assistiot/ | 38b003e55ff3 | openssl | 3.0.13-1~deb12u1 | 1 |
| assistiot/ | b1dbe4d62a03 | openssl | 3.0.13-1~deb12u1 | 1 |
| assistiot/ | e5ae539ce2cb | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| atlassian/ | 3b9222ab32ef | openssl | 3.0.2-0ubuntu1.14 | 1 |
| atlassian/ | 37bc46cbec1a | openssl | no fix listed | 1 |
| avinash263/ | aa2b8727f1a6 | openssl | 3.0.13-1~deb12u1 | 1 |
| avzini/ | f40b30210ed0 | openssl | 3.0.13-1~deb12u1 | 1 |